CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,515 vulnerabilities with CWE-89
CVE-2025-59387 HIGH
QNAP MARS 1.2.x < 1.2.1.1686 - SQL Injection
CVE-2025-65125 CRITICAL
gosaliajainam online-movie-booking 5.5 - SQL Injection via movie_details.php
CVSS 9.8
CVE-2025-15436 HIGH
Yonyou KSOA 9.0 - SQL Injection via Report Parameter in worksheet/work_edit.jsp
CVSS 7.3
CVE-2025-15435 HIGH
Yonyou KSOA 9.0 - SQL Injection via /worksheet/work_update.jsp Report Parameter
CVSS 7.3
CVE-2025-15434 HIGH
Yonyou KSOA 9.0 - SQL Injection via /kp/PrintZPYG.jsp zpjhid Parameter
CVSS 7.3
CVE-2025-15425 HIGH
Yonyou KSOA 9.0 - SQL Injection via /worksheet/del_user.jsp ID Parameter
CVSS 7.3
CVE-2025-15424 HIGH
Yonyou KSOA 9.0 - SQL Injection via worksheet/agent_worksdel.jsp ID Parameter
CVSS 7.3
CVE-2025-15421 HIGH
Yonyou KSOA 9.0 - SQL Injection via worksheetagent_worksadd.jsp ID Parameter
CVSS 7.3
CVE-2025-15420 HIGH
Yonyou KSOA 9.0 - SQL Injection via worksheetagent_work_report.jsp ID Parameter
CVSS 7.3
CVE-2025-55065 HIGH
ReKord client - SQL Injection
CVSS 7.5
CVE-2025-15410 HIGH
Online Guitar Store 1.0 - SQL Injection via L_email Parameter in /login.php
CVSS 7.3
CVE-2025-15409 HIGH
Online Guitar Store 1.0 - SQL Injection via /admin/Delete_product.php del_pro Parameter
CVSS 7.3
CVE-2025-15408 HIGH
Online Guitar Store 1.0 - SQL Injection via dre_title Parameter
CVSS 7.3
CVE-2025-15407 HIGH
Online Guitar Store 1.0 - SQL Injection via Create_category.php dre_Ctitle Parameter
CVSS 7.3
CVE-2025-30628 HIGH
AA-Team Amazon Affiliates Addon <1.2 - SQL Injection
CVSS 8.5
CVE-2025-28949 HIGH
Codedraft Mediabay - WordPress Media Library Folders <1.4 - SQL Inj...
CVSS 8.5
CVE-2025-15392 MEDIUM
KodiCMS < 13.82.135 - SQL Injection via Search API Endpoint Keyword Parameter
CVSS 6.3
CVE-2025-15354 HIGH
Society Management System 1.0 - SQL Injection via Username Parameter in add_admin.php
CVSS 7.3
CVE-2025-15353 HIGH
itsourcecode Society Management System 1.0 - SQL Injection via Username Parameter in edit_admin_query
CVSS 7.3
CVE-2025-15263 HIGH
BiggiDroid Simple PHP CMS 1.0 - SQL Injection via Admin Login Username Parameter
CVSS 7.3
CVE-2025-59129 HIGH
Appointify <= 1.0.8 - Blind SQL Injection
CVSS 7.6
CVE-2025-68990 HIGH
xenioushk BWL Pro Voting Manager <1.4.9 - SQL Injection
CVSS 8.5
CVE-2025-15243 HIGH
Simple Stock System 1.0 - SQL Injection via Username Parameter in Login
CVSS 7.3
CVE-2025-15212 MEDIUM
Refugee Food Management System 1.0 - SQL Injection via regfood.php 'a' Parameter
CVSS 6.3
CVE-2025-15211 MEDIUM
Refugee Food Management System 1.0 - SQL Injection via refNo/Fname/Lname/sex/age/contact/nationality_nid Parameters
CVSS 6.3
Details
Vulnerabilities 19,515
Exploit Likelihood High