CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,545 vulnerabilities with CWE-89
CVE-2025-13420 HIGH
itsourcecode Human Resource Management System 1.0 - SQL Injection via EventStore.php eventSubject Parameter
CVSS 7.3
CVE-2025-63719 HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-13410 HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via tid Parameter in /admin/receipt.php
CVSS 7.3
CVE-2025-65103 HIGH
OpenSTAManager < 2.9.5 - Authenticated SQL Injection via Display Parameter
CVSS 8.8
CVE-2025-12743 MEDIUM
Google Cloud Looker SQL Injection via Schemas Parameter
CVE-2025-65024 HIGH
i-educar < 2.10.0 - Authenticated Time-Based SQL Injection via cod_agenda Parameter
CVSS 7.2
CVE-2025-65023 HIGH
i-educar < 2.10.0 - Authenticated Time-Based SQL Injection via cod_funcionario_vinculo Parameter
CVSS 7.2
CVE-2025-65022 HIGH
i-educar < 2.10.0 - Authenticated SQL Injection via cod_agenda Parameter
CVSS 7.2
CVE-2025-63878 MEDIUM
Github Restaurant Website Restoran v1.0 - SQL Injection
CVSS 6.5
CVE-2025-13396 MEDIUM
Courier Management System 1.0 - SQL Injection via OfficeName Parameter in add-office.php
CVSS 6.3
CVE-2025-10437 CRITICAL
Webpack Management System <20251119 - SQL Injection
CVSS 9.8
CVE-2025-13395 HIGH
codehub666 94list - SQL Injection in Login Function
CVSS 7.3
CVE-2025-12646 HIGH
Community Events <1.5.4 - SQL Injection
CVSS 7.5
CVE-2025-65093 MEDIUM
LibreNMS < 25.11.0 - SQL Injection via Hostname Parameter in /ajax_output.php
CVSS 5.5
CVE-2025-63694 CRITICAL
dzzoffice < 2.3.7 - SQL Injection in explorer/groupmanage
CVSS 9.8
CVE-2025-63512 MEDIUM
kishan0725 Hospital Management System/v4 - SQL Injection
CVSS 6.5
CVE-2025-58692 HIGH
Fortinet FortiVoice <7.2.2 - SQL Injection
CVSS 8.8
CVE-2025-9977 MEDIUM
Times Software E-Payroll - Unauthenticated DoS & SQL Injection
CVE-2025-13347 MEDIUM
SourceCodester Train Station Ticketing System 1.0 - SQL Injection via Username Parameter in /ajax.php
CVSS 6.3
CVE-2025-13346 MEDIUM
SourceCodester Train Station Ticketing System 1.0 - SQL Injection via /ajax.php id/station Parameter
CVSS 6.3
CVE-2025-41348 CRITICAL
WinPlus 24.11.27 - SQL Injection via val1 and cont Parameters
CVSS 9.8
CVE-2025-13345 MEDIUM
SourceCodester Train Station Ticketing System 1.0 - SQL Injection via /ajax.php?action=save_ticket
CVSS 6.3
CVE-2025-13344 HIGH
SourceCodester Train Station Ticketing System 1.0 - SQL Injection via Username Parameter in /ajax.php
CVSS 7.3
CVE-2025-12411 HIGH
Premmerce Wholesale Pricing <1.1.10 - SQL Injection
CVSS 7.1
CVE-2025-13325 MEDIUM
Student Information System 1.0 - SQL Injection via en_id Parameter in enrollment_edit1.php
CVSS 6.3
Details
Vulnerabilities 19,545
Exploit Likelihood High