CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,544 vulnerabilities with CWE-89
CVE-2025-66440
HIGH
Frappe ERPNext <15.89.0 - SQL Injection
CVSS 8.8
CVE-2025-66439
HIGH
Frappe ERPNext <15.89.0 - SQL Injection
CVSS 8.8
CVE-2025-34179
HIGH
NetSupport Manager <14.12.0001 - SQL Injection
CVE-2025-14383
HIGH
Booking Calendar <10.14.8 - SQL Injection
CVSS 7.5
CVE-2025-14711
HIGH
FantasticLBP Hotels Server <67b44df162fab26df209bd5d5d542875fcbec1d...
CVSS 7.3
CVE-2025-14710
HIGH
FantasticLBP Hotels Server - SQL Injection
CVSS 7.3
CVE-2025-14694
MEDIUM
ketr JEPaaS <= 7.2.8 - SQL Injection via readAllPostil keyWord Parameter
CVSS 4.7
CVE-2025-14668
HIGH
campcodes Advanced Online Examination System 1.0 - SQL Injection via Username Parameter in loginExe.php
CVSS 7.3
CVE-2025-14667
HIGH
itsourcecode COVID Tracking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14666
HIGH
itsourcecode COVID Tracking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14664
HIGH
Campcodes Supplier Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14661
HIGH
itsourcecode Student Managemen System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14653
HIGH
isourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14652
HIGH
itsourcecode Online Cake Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14650
HIGH
iSourcecode Online Cake Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14649
HIGH
itsourcecode Online Cake Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14647
HIGH
Computer Book Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14646
HIGH
Code-projects Student File Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14645
HIGH
Student File Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-13126
HIGH
wpForo Forum <2.4.12 - SQL Injection
CVSS 7.5
CVE-2025-14644
HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14643
HIGH
Simple Attendance Record System 2.0 - SQL Injection
CVSS 7.3
CVE-2025-14640
HIGH
Code-projects Student File Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14639
HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14638
HIGH
itsourcecode Online Pet Shop Management System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities
19,544
Exploit Likelihood
High