CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,515 vulnerabilities with CWE-89
CVE-2025-14990
HIGH
Complete Online Beauty Parlor Management System 1.0 - SQL Injection via viewid Parameter
CVSS 7.3
CVE-2025-14989
HIGH
Campcodes Complete Online Beauty Parlor Management System 1.0 - SQL Injection via /admin/search-invoices.php
CVSS 7.3
CVE-2025-14968
HIGH
Simple Stock System 1.0 - SQL Injection via Email Parameter in Update Endpoint
CVSS 7.3
CVE-2025-14967
HIGH
Student Management System 1.0 - SQL Injection via school_year Parameter in candidates_report.php
CVSS 7.3
CVE-2025-14966
MEDIUM
fastadmin < 1.6.1.20250430 - SQL Injection via Backend Controller selectpage Function
CVSS 4.7
CVE-2025-14961
HIGH
Simple Blood Donor Management System 1.0 - SQL Injection via campaignname Parameter in /editedcampaign.php
CVSS 7.3
CVE-2025-14960
HIGH
Simple Blood Donor Management System 1.0 - SQL Injection via Name Parameter in editeddonor.php
CVSS 7.3
CVE-2025-14959
HIGH
Simple Stock System 1.0 - SQL Injection via Username Parameter in signup.php
CVSS 7.3
CVE-2025-14952
HIGH
Campcodes Supplier Management System 1.0 - SQL Injection via txtCategoryName Parameter
CVSS 7.3
CVE-2025-14951
HIGH
Scholars Tracking System 1.0 - SQL Injection via post_content Parameter
CVSS 7.3
CVE-2025-14950
HIGH
Scholars Tracking System 1.0 - SQL Injection via /delete_post.php ID Parameter
CVSS 7.3
CVE-2025-14940
HIGH
Scholars Tracking System 1.0 - SQL Injection via /admin/delete_user.php ID Parameter
CVSS 7.3
CVE-2025-14939
MEDIUM
Online Appointment Booking System 1.0 - SQL Injection via Managername Parameter
CVSS 4.7
CVE-2025-14900
MEDIUM
CodeAstro Real Estate Management System 1.0 - SQL Injection via /admin/userdelete.php ID Parameter
CVSS 4.7
CVE-2025-14899
MEDIUM
CodeAstro Real Estate Management System 1.0 - SQL Injection in Administrator Endpoint
CVSS 4.7
CVE-2025-14898
MEDIUM
CodeAstro Real Estate Management System 1.0 - SQL Injection in Administrator Endpoint
CVSS 4.7
CVE-2025-14897
MEDIUM
CodeAstro Real Estate Management System 1.0 - SQL Injection via /admin/useragentdelete.php
CVSS 4.7
CVE-2025-63948
MEDIUM
phpMsAdmin 2.2 - SQL Injection via dbname Parameter
CVSS 5.4
CVE-2025-46268
MEDIUM
Advantech WebAccess/SCADA - SQL Injection
CVSS 6.3
CVE-2025-14877
HIGH
Campcodes Supplier Management System 1.0 - SQL Injection via cmbAreaCode Parameter
CVSS 7.3
CVE-2025-64371
HIGH
shinetheme Traveler <3.2.6 - SQL Injection
CVSS 8.5
CVE-2025-60062
CRITICAL
mmetrodw tPlayer <= 1.2.1.6 - SQL Injection
CVSS 9.3
CVE-2025-58951
CRITICAL
smartcms Advance Seat Reservation Management - SQL Injection
CVSS 9.3
CVE-2025-14314
HIGH
Roxnor PopupKit <2.1.5 - SQL Injection
CVSS 8.5
CVE-2025-14834
MEDIUM
Simple Stock System 1.0 - SQL Injection via Username Parameter in checkuser.php
CVSS 6.3
Details
Vulnerabilities
19,515
Exploit Likelihood
High