CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,544 vulnerabilities with CWE-89
CVE-2025-14068 HIGH
WPNakama < 0.6.3 - Unauthenticated Time-Based SQL Injection via Order By Parameter
CVSS 7.5
CVE-2025-62192 MEDIUM
GroupSession <5.3.0-5.3.2 - SQL Injection
CVSS 5.4
CVE-2025-14537 HIGH
Code-projects Class and Exam Timetable Management 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14536 HIGH
Class and Exam Timetable Management 1.0 - SQL Injection
CVSS 7.3
CVE-2025-13214 HIGH
IBM Aspera Orchestrator 4.0.0-4.1.0 - SQL Injection
CVSS 7.6
CVE-2025-14529 HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14527 HIGH
Projectworlds Advanced Library Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14515 HIGH
Campcodes Supplier Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14514 HIGH
Campcodes Supplier Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-10163 MEDIUM
List category posts plugin <0.91.0 - SQL Injection
CVSS 6.5
CVE-2025-67644 HIGH
langgraph-checkpoint-sqlite < 3.0.1 - SQL Injection via Metadata Filter Key Interpolation
CVSS 7.3
CVE-2025-65950 HIGH
WBCE CMS < 1.6.5 - Authenticated SQL Injection via User Management groups[] Parameter
CVSS 8.8
CVE-2025-67501 HIGH
WeGIA < 3.5.5 - SQL Injection via id_categoria Parameter
CVSS 8.8
CVE-2025-14337 HIGH
isourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14336 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14335 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14334 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-64156 HIGH
FortiVoice 6.0.0-6.0.11, 6.4.0-6.4.x, 7.0.0-7.0.7, 7.2.0-7.2.2 - Authenticated SQL Injection
CVSS 7.2
CVE-2025-63742 CRITICAL
Xinhu Rainrock RockOA 2.7.0 - SQL Injection
CVSS 9.8
CVE-2025-63740 MEDIUM
Xinhu Rainrock RockOA <2.7.0 - SQL Injection
CVSS 4.3
CVE-2025-67520 HIGH
Media Library Tools <1.6.15 - SQL Injection
CVSS 7.6
CVE-2025-67519 HIGH
Shahjahan Jewel Ninja Tables <5.2.3 - SQL Injection
CVSS 7.6
CVE-2025-67518 HIGH
LambertGroup Accordion Slider PRO - SQL Injection
CVSS 8.5
CVE-2025-67517 HIGH
ArtPlacer Widget <2.22.9.2 - SQL Injection
CVSS 8.5
CVE-2025-67516 HIGH
Agile Logix Store Locator <1.6.2 - SQL Injection
CVSS 8.5
Details
Vulnerabilities 19,544
Exploit Likelihood High