CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,515 vulnerabilities with CWE-89
CVE-2025-14833 HIGH
Online Appointment Booking System 1.0 - SQL Injection via /admin/deletemanagerclinic.php Clinic Parameter
CVSS 7.3
CVE-2025-68400 HIGH
ChurchCRM < 6.5.3 - Authenticated SQL Injection via Legacy Reports Endpoint
CVSS 8.8
CVE-2025-68112 CRITICAL
ChurchCRM < 6.5.3 - Authenticated SQL Injection via Event Attendee Editor
CVSS 9.6
CVE-2025-68111 HIGH
ChurchCRM < 6.5.3 - Authenticated SQL Injection via MissingEgive_FamID_... POST Parameter
CVSS 7.2
CVE-2025-67877 HIGH
ChurchCRM < 6.5.3 - SQL Injection via PersonAddress POST Parameter
CVSS 8.8
CVE-2025-14832 HIGH
Online Cake Ordering System 1.0 - SQL Injection via updateproduct.php ID Parameter
CVSS 7.3
CVE-2025-66396 HIGH
ChurchCRM < 6.5.3 - Authenticated SQL Injection via UserEditor.php Type Parameter
CVSS 7.2
CVE-2025-66395 HIGH
ChurchCRM < 6.5.3 - Authenticated SQL Injection via WhichType POST Parameter
CVSS 8.8
CVE-2025-67285 HIGH
ITSourcecode COVID Tracking System Using QR-Code 1.0 - SQL Injection via Zone Page ID Parameter
CVSS 7.3
CVE-2025-14780 MEDIUM
Xiongwei Smart Catering Cloud Platform 2.1.6446.28761 - SQL Injection
CVSS 6.3
CVE-2025-68056 HIGH
LambertGroup LBG Zoominoutslider <5.4.5 - SQL Injection
CVSS 8.5
CVE-2025-68055 HIGH
Themefic Hydra Booking <1.1.32 - SQL Injection
CVSS 8.5
CVE-2025-68054 HIGH
LambertGroup CountDown With Image or Video Background - SQL Injection
CVSS 8.5
CVE-2025-68053 HIGH
LambertGroup xPromoter <= 1.3.4 - SQL Injection
CVSS 8.5
CVE-2025-67999 HIGH
Stefano Lissa Newsletter <10 - SQL Injection
CVSS 7.6
CVE-2025-67962 HIGH
AIOSEO Plugin Team Broken Link Checker <1.2.6 - SQL Injection
CVSS 7.6
CVE-2025-67950 HIGH
All In One SEO Pack <4.9.1 - SQL Injection
CVSS 8.5
CVE-2025-62849 CRITICAL
QNAP QTS and QuTS hero - SQL Injection
CVSS 9.8
CVE-2025-67751 HIGH
ChurchCRM < 6.5.0 - Authenticated SQL Injection via EN_tyid POST Parameter
CVSS 7.2
CVE-2025-67736 HIGH
FreePBX 16.0-16.0.4 - Authenticated SQL Injection via TTS Module
CVSS 7.2
CVE-2025-55703 LOW
Sunbird Power IQ <9.2.0 - SQL Injection
CVSS 2.5
CVE-2025-66440 HIGH
Frappe ERPNext <15.89.0 - SQL Injection
CVSS 8.8
CVE-2025-66439 HIGH
Frappe ERPNext <15.89.0 - SQL Injection
CVSS 8.8
CVE-2025-34179 HIGH
NetSupport Manager <14.12.0001 - SQL Injection
CVE-2025-14383 HIGH
Booking Calendar <10.14.8 - SQL Injection
CVSS 7.5
Details
Vulnerabilities 19,515
Exploit Likelihood High