CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,515 vulnerabilities with CWE-89
CVE-2025-14711 HIGH
FantasticLBP Hotels Server <67b44df162fab26df209bd5d5d542875fcbec1d...
CVSS 7.3
CVE-2025-14710 HIGH
FantasticLBP Hotels Server - SQL Injection
CVSS 7.3
CVE-2025-14694 MEDIUM
ketr JEPaaS <= 7.2.8 - SQL Injection via readAllPostil keyWord Parameter
CVSS 4.7
CVE-2025-14668 HIGH
campcodes Advanced Online Examination System 1.0 - SQL Injection via Username Parameter in loginExe.php
CVSS 7.3
CVE-2025-14667 HIGH
itsourcecode COVID Tracking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14666 HIGH
itsourcecode COVID Tracking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14664 HIGH
Campcodes Supplier Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14661 HIGH
itsourcecode Student Managemen System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14653 HIGH
isourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14652 HIGH
itsourcecode Online Cake Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14650 HIGH
iSourcecode Online Cake Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14649 HIGH
itsourcecode Online Cake Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14647 HIGH
Computer Book Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14646 HIGH
Code-projects Student File Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14645 HIGH
Student File Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-13126 HIGH
wpForo Forum <2.4.12 - SQL Injection
CVSS 7.5
CVE-2025-14644 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14643 HIGH
Simple Attendance Record System 2.0 - SQL Injection
CVSS 7.3
CVE-2025-14640 HIGH
Code-projects Student File Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14639 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14638 HIGH
itsourcecode Online Pet Shop Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14637 HIGH
isourcecode Online Pet Shop Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14623 HIGH
Code-projects Student File Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14622 HIGH
Student File Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14621 HIGH
Code-Projects Student File Mgmt - SQL Injection
CVSS 7.3
Details
Vulnerabilities 19,515
Exploit Likelihood High