CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,544 vulnerabilities with CWE-89
CVE-2025-62093 HIGH
LambertGroup Image&Video FullScreen Background - SQL Injection
CVSS 8.5
CVE-2025-12807 HIGH
DataMosaix Private Cloud - Privilege Escalation
CVE-2025-12504 CRITICAL
Talent Software UNIS <42321 - SQL Injection
CVSS 9.8
CVE-2025-10655 HIGH
Frappe HelpDesk <1.14.0 - SQL Injection
CVSS 8.8
CVE-2025-14285 HIGH
code-projects Employee Profile Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-64081 CRITICAL
Patients Waiting Area Queue Management System - SQL Injection via appointmentID Parameter
CVSS 9.8
CVE-2025-14259 MEDIUM
Jihai Jshop MiniProgram Mall System 2.9.0 - SQL Injection
CVSS 6.3
CVE-2025-14258 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14257 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14256 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14251 HIGH
Code-projects Online Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14250 HIGH
Code-projects Online Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14249 HIGH
Code-projects Online Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14248 HIGH
Simple Shopping Cart 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14247 MEDIUM
Simple Shopping Cart 1.0 - SQL Injection
CVSS 6.3
CVE-2025-14246 MEDIUM
Simple Shopping Cart 1.0 - SQL Injection
CVSS 6.3
CVE-2025-14245 HIGH
ideacms < 1.8 - SQL Injection via Coupon.php whereRaw Function
CVSS 7.3
CVE-2025-14230 MEDIUM
Code-projects Daily Time Recording System 4.5.0 - SQL Injection
CVSS 6.3
CVE-2025-14227 MEDIUM
Philipinho Simple-PHP-Blog < 2025-01-22 - SQL Injection via /edit.php
CVSS 6.3
CVE-2025-14226 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14255 MEDIUM
Vitals ESP - SQL Injection
CVSS 6.5
CVE-2025-14254 MEDIUM
Vitals ESP - SQL Injection
CVSS 6.5
CVE-2025-14223 HIGH
Simple Leave Manager 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14222 MEDIUM
Code-Projects Employee Profile Mgmt - SQL Injection
CVSS 6.3
CVE-2025-14218 HIGH
Currency Exchange System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 19,544
Exploit Likelihood High