CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,515 vulnerabilities with CWE-89
CVE-2025-59387
HIGH
QNAP MARS 1.2.x < 1.2.1.1686 - SQL Injection
CVE-2025-65125
CRITICAL
gosaliajainam online-movie-booking 5.5 - SQL Injection via movie_details.php
CVSS 9.8
CVE-2025-15436
HIGH
Yonyou KSOA 9.0 - SQL Injection via Report Parameter in worksheet/work_edit.jsp
CVSS 7.3
CVE-2025-15435
HIGH
Yonyou KSOA 9.0 - SQL Injection via /worksheet/work_update.jsp Report Parameter
CVSS 7.3
CVE-2025-15434
HIGH
Yonyou KSOA 9.0 - SQL Injection via /kp/PrintZPYG.jsp zpjhid Parameter
CVSS 7.3
CVE-2025-15425
HIGH
Yonyou KSOA 9.0 - SQL Injection via /worksheet/del_user.jsp ID Parameter
CVSS 7.3
CVE-2025-15424
HIGH
Yonyou KSOA 9.0 - SQL Injection via worksheet/agent_worksdel.jsp ID Parameter
CVSS 7.3
CVE-2025-15421
HIGH
Yonyou KSOA 9.0 - SQL Injection via worksheetagent_worksadd.jsp ID Parameter
CVSS 7.3
CVE-2025-15420
HIGH
Yonyou KSOA 9.0 - SQL Injection via worksheetagent_work_report.jsp ID Parameter
CVSS 7.3
CVE-2025-55065
HIGH
ReKord client - SQL Injection
CVSS 7.5
CVE-2025-15410
HIGH
Online Guitar Store 1.0 - SQL Injection via L_email Parameter in /login.php
CVSS 7.3
CVE-2025-15409
HIGH
Online Guitar Store 1.0 - SQL Injection via /admin/Delete_product.php del_pro Parameter
CVSS 7.3
CVE-2025-15408
HIGH
Online Guitar Store 1.0 - SQL Injection via dre_title Parameter
CVSS 7.3
CVE-2025-15407
HIGH
Online Guitar Store 1.0 - SQL Injection via Create_category.php dre_Ctitle Parameter
CVSS 7.3
CVE-2025-30628
HIGH
AA-Team Amazon Affiliates Addon <1.2 - SQL Injection
CVSS 8.5
CVE-2025-28949
HIGH
Codedraft Mediabay - WordPress Media Library Folders <1.4 - SQL Inj...
CVSS 8.5
CVE-2025-15392
MEDIUM
KodiCMS < 13.82.135 - SQL Injection via Search API Endpoint Keyword Parameter
CVSS 6.3
CVE-2025-15354
HIGH
Society Management System 1.0 - SQL Injection via Username Parameter in add_admin.php
CVSS 7.3
CVE-2025-15353
HIGH
itsourcecode Society Management System 1.0 - SQL Injection via Username Parameter in edit_admin_query
CVSS 7.3
CVE-2025-15263
HIGH
BiggiDroid Simple PHP CMS 1.0 - SQL Injection via Admin Login Username Parameter
CVSS 7.3
CVE-2025-59129
HIGH
Appointify <= 1.0.8 - Blind SQL Injection
CVSS 7.6
CVE-2025-68990
HIGH
xenioushk BWL Pro Voting Manager <1.4.9 - SQL Injection
CVSS 8.5
CVE-2025-15243
HIGH
Simple Stock System 1.0 - SQL Injection via Username Parameter in Login
CVSS 7.3
CVE-2025-15212
MEDIUM
Refugee Food Management System 1.0 - SQL Injection via regfood.php 'a' Parameter
CVSS 6.3
CVE-2025-15211
MEDIUM
Refugee Food Management System 1.0 - SQL Injection via refNo/Fname/Lname/sex/age/contact/nationality_nid Parameters
CVSS 6.3
Details
Vulnerabilities
19,515
Exploit Likelihood
High