CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,515 vulnerabilities with CWE-89
CVE-2025-14833
HIGH
Online Appointment Booking System 1.0 - SQL Injection via /admin/deletemanagerclinic.php Clinic Parameter
CVSS 7.3
CVE-2025-68400
HIGH
ChurchCRM < 6.5.3 - Authenticated SQL Injection via Legacy Reports Endpoint
CVSS 8.8
CVE-2025-68112
CRITICAL
ChurchCRM < 6.5.3 - Authenticated SQL Injection via Event Attendee Editor
CVSS 9.6
CVE-2025-68111
HIGH
ChurchCRM < 6.5.3 - Authenticated SQL Injection via MissingEgive_FamID_... POST Parameter
CVSS 7.2
CVE-2025-67877
HIGH
ChurchCRM < 6.5.3 - SQL Injection via PersonAddress POST Parameter
CVSS 8.8
CVE-2025-14832
HIGH
Online Cake Ordering System 1.0 - SQL Injection via updateproduct.php ID Parameter
CVSS 7.3
CVE-2025-66396
HIGH
ChurchCRM < 6.5.3 - Authenticated SQL Injection via UserEditor.php Type Parameter
CVSS 7.2
CVE-2025-66395
HIGH
ChurchCRM < 6.5.3 - Authenticated SQL Injection via WhichType POST Parameter
CVSS 8.8
CVE-2025-67285
HIGH
ITSourcecode COVID Tracking System Using QR-Code 1.0 - SQL Injection via Zone Page ID Parameter
CVSS 7.3
CVE-2025-14780
MEDIUM
Xiongwei Smart Catering Cloud Platform 2.1.6446.28761 - SQL Injection
CVSS 6.3
CVE-2025-68056
HIGH
LambertGroup LBG Zoominoutslider <5.4.5 - SQL Injection
CVSS 8.5
CVE-2025-68055
HIGH
Themefic Hydra Booking <1.1.32 - SQL Injection
CVSS 8.5
CVE-2025-68054
HIGH
LambertGroup CountDown With Image or Video Background - SQL Injection
CVSS 8.5
CVE-2025-68053
HIGH
LambertGroup xPromoter <= 1.3.4 - SQL Injection
CVSS 8.5
CVE-2025-67999
HIGH
Stefano Lissa Newsletter <10 - SQL Injection
CVSS 7.6
CVE-2025-67962
HIGH
AIOSEO Plugin Team Broken Link Checker <1.2.6 - SQL Injection
CVSS 7.6
CVE-2025-67950
HIGH
All In One SEO Pack <4.9.1 - SQL Injection
CVSS 8.5
CVE-2025-62849
CRITICAL
QNAP QTS and QuTS hero - SQL Injection
CVSS 9.8
CVE-2025-67751
HIGH
ChurchCRM < 6.5.0 - Authenticated SQL Injection via EN_tyid POST Parameter
CVSS 7.2
CVE-2025-67736
HIGH
FreePBX 16.0-16.0.4 - Authenticated SQL Injection via TTS Module
CVSS 7.2
CVE-2025-55703
LOW
Sunbird Power IQ <9.2.0 - SQL Injection
CVSS 2.5
CVE-2025-66440
HIGH
Frappe ERPNext <15.89.0 - SQL Injection
CVSS 8.8
CVE-2025-66439
HIGH
Frappe ERPNext <15.89.0 - SQL Injection
CVSS 8.8
CVE-2025-34179
HIGH
NetSupport Manager <14.12.0001 - SQL Injection
CVE-2025-14383
HIGH
Booking Calendar <10.14.8 - SQL Injection
CVSS 7.5
Details
Vulnerabilities
19,515
Exploit Likelihood
High