CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,510 vulnerabilities with CWE-89
CVE-2025-15441 MEDIUM
Form Maker < 1.15.38 - SQL Injection
CVSS 6.8
CVE-2025-13855 HIGH
IBM Storage Protect Server is affected by a vulnerability that could allow authenticated users to access administrative metadata through the JSON-RPC endpoint .
CVSS 7.6
CVE-2025-55262 HIGH
HCL Aftermarket DPC is affected by SQL Injection
CVSS 8.3
CVE-2025-41008 CRITICAL
SQL Injection in Sinturno
CVE-2025-41007 CRITICAL
SQL Injection in Cuantis
CVE-2025-62846 MEDIUM
QNAP QuRouter < 2.6.2.007 - Local Admin SQL Injection
CVSS 6.7
CVE-2025-58112 HIGH
Microsoft Dynamics 365 9.0.2.3034 - SQL Injection
CVSS 8.8
CVE-2025-67830 CRITICAL
Mura CMS < 10.1.4 - SQL Injection via beanFeed.cfc getQuery sortby
CVSS 9.8
CVE-2025-67829 CRITICAL
Mura CMS < 10.1.4 - SQL Injection via beanFeed.cfc getQuery sortDirection
CVSS 9.8
CVE-2025-69768 HIGH
chyrp < 2.5.2 - SQL Injection via Admin.php
CVSS 7.5
CVE-2025-62319 CRITICAL
Boolean-Based SQL Injection in Multiple Unica Components
CVSS 9.8
CVE-2025-52646 LOW
HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries.
CVSS 2.2
CVE-2025-52637 MEDIUM
Multiple security vulnerabilities affect HCL AION
CVSS 4.5
CVE-2025-36368 MEDIUM
IBM Sterling B2B Integrator 6.1.0.0-6.1.2.7_2 - SQL Injection
CVSS 6.5
CVE-2025-70024 CRITICAL
benkeen generatedata 4.0.14 - SQL Injection
CVSS 9.8
CVE-2025-56421 HIGH
LimeSurvey <6.15.4+250710 - SQL Injection
CVSS 7.5
CVE-2025-49784 MEDIUM
Fortinet FortiAnalyzer - SQL Injection
CVSS 6.0
CVE-2025-40639 CRITICAL
Eventobot - SQL Injection via Promo Send Parameter
CVSS 9.8
CVE-2025-14353 HIGH
WordPress ZIP Code Based Content Protection <=1.0.2 - SQL Injection
CVSS 7.5
CVE-2025-69338 CRITICAL
Riode Core <=1.6.26 - SQL Injection
CVSS 9.3
CVE-2025-66944 CRITICAL
vran-dev databaseir <=1.0.7 - SQL Injection
CVSS 9.8
CVE-2025-66678 CRITICAL
Nil Hardware Editor <1.25.11.26 - Memory Corruption
CVSS 9.8
CVE-2025-70821 CRITICAL
renren-security <5.5.0 - SQL Injection
CVSS 9.8
CVE-2025-48650 HIGH
Android - SQL Injection Leading to Local Privilege Escalation
CVSS 8.4
CVE-2025-50192 CRITICAL
Chamilo < 1.11.30 - Time-Based SQL Injection via Registration SOAP Endpoint
CVSS 9.8
Details
Vulnerabilities 19,510
Exploit Likelihood High