CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,545 vulnerabilities with CWE-89
CVE-2025-14218 HIGH
Currency Exchange System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14217 HIGH
Currency Exchange System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14216 HIGH
Currency Exchange System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14215 HIGH
Currency Exchange System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14214 MEDIUM
itsourcecode Student Information System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-14212 HIGH
Advanced Library Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14211 HIGH
Advanced Library Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14210 HIGH
projectworlds Advanced Library Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14209 HIGH
Campcodes School File Mgmt Sys 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14207 HIGH
tushar-2223 Hotel-Management-System - SQL Injection in /admin/invoiceprint.php
CVSS 7.3
CVE-2025-14203 MEDIUM
Code-Projects Question Paper Generator <1.0 - SQL Injection
CVSS 6.3
CVE-2025-14193 MEDIUM
Employee Profile Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-14192 HIGH
RashminDungrani online-banking - SQL Injection in /site/dist/auth_login.php
CVSS 7.3
CVE-2025-14190 HIGH
Chanjet TPlus <20251121 - SQL Injection
CVSS 7.3
CVE-2025-14189 HIGH
Chanjet CRM <20251121 - SQL Injection
CVSS 7.3
CVE-2025-14185 MEDIUM
Yonyou U8 Cloud <5.1sp - SQL Injection
CVSS 6.3
CVE-2025-13922 MEDIUM
Tag, Category, Taxonomy Manager - WordPress <3.40.1 - SQL Injection
CVSS 6.5
CVE-2025-14091 HIGH
TrippWasTaken PHP-Guitar-Shop - SQL Injection in Product Details Page
CVSS 7.3
CVE-2025-14090 MEDIUM
Amttgroup Hibos - Injection
CVSS 4.7
CVE-2025-12850 HIGH
My auctions allegro plugin <3.6.32 - SQL Injection
CVSS 7.5
CVE-2025-13373 HIGH
Advantech iView <5.7.05.7057 - SQL Injection
CVSS 7.5
CVE-2025-14012 MEDIUM
jizhicms < 2.5.5 - SQL Injection via Batch Delete Comments Function
CVSS 4.7
CVE-2025-14011 MEDIUM
jizhicms < 2.5.5 - SQL Injection via Add Display Name Field aid/tid Parameter
CVSS 4.7
CVE-2025-62173 HIGH
Endpoint Module <Rest API - SQL Injection
CVE-2025-13359 MEDIUM
Taxopress < 3.41.0 - SQL Injection
CVSS 6.5
Details
Vulnerabilities 19,545
Exploit Likelihood High