CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,545 vulnerabilities with CWE-89
CVE-2025-13571 MEDIUM
Simple Food Ordering System 1.0 - SQL Injection via ID Parameter in listorder.php
CVSS 6.3
CVE-2025-13570 MEDIUM
COVID Tracking System 1.0 - SQL Injection via /admin/?page=state ID Parameter
CVSS 6.3
CVE-2025-13569 MEDIUM
COVID Tracking System 1.0 - SQL Injection via /admin/?page=city ID Parameter
CVSS 6.3
CVE-2025-13568 MEDIUM
itsourcecode COVID Tracking System 1.0 - SQL Injection via ID Parameter in Admin People Page
CVSS 6.3
CVE-2025-13567 MEDIUM
itsourcecode COVID Tracking System 1.0 - SQL Injection via ID Parameter in Establishment Page
CVSS 6.3
CVE-2025-13561 HIGH
SourceCodester Company Website CMS 1.0 - SQL Injection via Username Parameter in /admin/index.php
CVSS 7.3
CVE-2025-13560 HIGH
SourceCodester Company Website CMS 1.0 - SQL Injection via Reset Password Email Parameter
CVSS 7.3
CVE-2025-13557 HIGH
Campcodes Online Polling System 1.0 - SQL Injection via Email Parameter in Registeracc.php
CVSS 7.3
CVE-2025-13556 HIGH
Campcodes Online Polling System 1.0 - SQL Injection via myusername Parameter
CVSS 7.3
CVE-2025-13555 HIGH
Campcodes School File Management System 1.0 - SQL Injection via stud_no Parameter
CVSS 7.3
CVE-2025-13554 HIGH
Campcodes Supplier Management System 1.0 - SQL Injection via txtUsername Parameter in Login Component
CVSS 7.3
CVE-2025-13546 MEDIUM
ashraf-kabir travel-agency - SQL Injection via Search Component user_query Parameter
CVSS 6.3
CVE-2025-13545 MEDIUM
ashraf-kabir travel-agency < 2025-07-05 - SQL Injection via edit_pack Parameter
CVSS 4.7
CVE-2025-66095 HIGH
Iqonic Design KiviCare <3.6.13 - SQL Injection
CVSS 8.5
CVE-2025-13138 HIGH
WP Directory Kit <1.4.3 - SQL Injection
CVSS 7.5
CVE-2025-12750 MEDIUM
Groundhogg - CRM, Newsletters, and Marketing Automation <= 4.2.6.1 - Authenticated SQL Injection via Term Parameter
CVSS 4.9
CVE-2025-13485 HIGH
itsourcecode Online File Management System 1.0 - SQL Injection via Username Parameter in ajax.php
CVSS 7.3
CVE-2025-52410 CRITICAL
Institute-of-Current-Students v1.0 - Time-Based Blind SQL Injection via myds GET Parameter
CVSS 9.8
CVE-2025-60798 MEDIUM
phppgadmin < 7.13.0 - Authenticated SQL Injection via display.php
CVSS 6.5
CVE-2025-60797 MEDIUM
phppgadmin < 7.13.0 - Authenticated SQL Injection via dataexport.php Query Parameter
CVSS 6.5
CVE-2025-13451 HIGH
SourceCodester Online Shop Project 1.0 - SQL Injection via Search Parameter in action.php
CVSS 7.3
CVE-2025-13449 HIGH
Online Shop Project 1.0 - SQL Injection via Login Password Parameter
CVSS 7.3
CVE-2025-13424 MEDIUM
Campcodes Supplier Management System 1.0 - SQL Injection via txtProductName Parameter
CVSS 4.7
CVE-2025-13422 HIGH
Sports Club Management System 1.0 - SQL Injection via login_id Parameter
CVSS 7.3
CVE-2025-13421 HIGH
Human Resource Management System 1.0 - SQL Injection via NoticeDesc Parameter
CVSS 7.3
Details
Vulnerabilities 19,545
Exploit Likelihood High