CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,545 vulnerabilities with CWE-89
CVE-2025-13571
MEDIUM
Simple Food Ordering System 1.0 - SQL Injection via ID Parameter in listorder.php
CVSS 6.3
CVE-2025-13570
MEDIUM
COVID Tracking System 1.0 - SQL Injection via /admin/?page=state ID Parameter
CVSS 6.3
CVE-2025-13569
MEDIUM
COVID Tracking System 1.0 - SQL Injection via /admin/?page=city ID Parameter
CVSS 6.3
CVE-2025-13568
MEDIUM
itsourcecode COVID Tracking System 1.0 - SQL Injection via ID Parameter in Admin People Page
CVSS 6.3
CVE-2025-13567
MEDIUM
itsourcecode COVID Tracking System 1.0 - SQL Injection via ID Parameter in Establishment Page
CVSS 6.3
CVE-2025-13561
HIGH
SourceCodester Company Website CMS 1.0 - SQL Injection via Username Parameter in /admin/index.php
CVSS 7.3
CVE-2025-13560
HIGH
SourceCodester Company Website CMS 1.0 - SQL Injection via Reset Password Email Parameter
CVSS 7.3
CVE-2025-13557
HIGH
Campcodes Online Polling System 1.0 - SQL Injection via Email Parameter in Registeracc.php
CVSS 7.3
CVE-2025-13556
HIGH
Campcodes Online Polling System 1.0 - SQL Injection via myusername Parameter
CVSS 7.3
CVE-2025-13555
HIGH
Campcodes School File Management System 1.0 - SQL Injection via stud_no Parameter
CVSS 7.3
CVE-2025-13554
HIGH
Campcodes Supplier Management System 1.0 - SQL Injection via txtUsername Parameter in Login Component
CVSS 7.3
CVE-2025-13546
MEDIUM
ashraf-kabir travel-agency - SQL Injection via Search Component user_query Parameter
CVSS 6.3
CVE-2025-13545
MEDIUM
ashraf-kabir travel-agency < 2025-07-05 - SQL Injection via edit_pack Parameter
CVSS 4.7
CVE-2025-66095
HIGH
Iqonic Design KiviCare <3.6.13 - SQL Injection
CVSS 8.5
CVE-2025-13138
HIGH
WP Directory Kit <1.4.3 - SQL Injection
CVSS 7.5
CVE-2025-12750
MEDIUM
Groundhogg - CRM, Newsletters, and Marketing Automation <= 4.2.6.1 - Authenticated SQL Injection via Term Parameter
CVSS 4.9
CVE-2025-13485
HIGH
itsourcecode Online File Management System 1.0 - SQL Injection via Username Parameter in ajax.php
CVSS 7.3
CVE-2025-52410
CRITICAL
Institute-of-Current-Students v1.0 - Time-Based Blind SQL Injection via myds GET Parameter
CVSS 9.8
CVE-2025-60798
MEDIUM
phppgadmin < 7.13.0 - Authenticated SQL Injection via display.php
CVSS 6.5
CVE-2025-60797
MEDIUM
phppgadmin < 7.13.0 - Authenticated SQL Injection via dataexport.php Query Parameter
CVSS 6.5
CVE-2025-13451
HIGH
SourceCodester Online Shop Project 1.0 - SQL Injection via Search Parameter in action.php
CVSS 7.3
CVE-2025-13449
HIGH
Online Shop Project 1.0 - SQL Injection via Login Password Parameter
CVSS 7.3
CVE-2025-13424
MEDIUM
Campcodes Supplier Management System 1.0 - SQL Injection via txtProductName Parameter
CVSS 4.7
CVE-2025-13422
HIGH
Sports Club Management System 1.0 - SQL Injection via login_id Parameter
CVSS 7.3
CVE-2025-13421
HIGH
Human Resource Management System 1.0 - SQL Injection via NoticeDesc Parameter
CVSS 7.3
Details
Vulnerabilities
19,545
Exploit Likelihood
High