CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,545 vulnerabilities with CWE-89
CVE-2025-11454 MEDIUM
WordPress Customize Mobile - SQL Injection
CVSS 6.5
CVE-2025-59499 HIGH
Microsoft SQL Server 2016-2022 Authenticated SQL Injection
CVSS 8.8
CVE-2025-8324 CRITICAL
Zohocorp ManageEngine Analytics Plus <6170 - SQL Injection
CVSS 9.8
CVE-2025-42889 MEDIUM
SAP Starter Solution - SQL Injection
CVSS 5.4
CVE-2025-64519 HIGH
TorrentPier <= 2.8.8 - Authenticated SQL Injection via Moderator Control Panel Topic ID Parameter
CVSS 8.8
CVE-2025-63497 HIGH
Rickxy Hospital Management System <1.0 - SQL Injection
CVSS 7.1
CVE-2025-12939 MEDIUM
SourceCodester Interview Management System <1.0 - SQL Injection
CVSS 6.3
CVE-2025-12938 HIGH
Projectworlds Online Admission System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12409 HIGH
Looker Studio < 2025-07-07 - SQL Injection via Malicious Report with Native Functions
CVE-2025-12397 HIGH
Looker Studio < 2025-07-21 - Authenticated SQL Injection via BigQuery Report View
CVE-2025-12933 MEDIUM
SourceCodester Baby Care System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-12932 MEDIUM
SourceCodester Baby Care System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12931 MEDIUM
SourceCodester Food Ordering System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-12930 MEDIUM
SourceCodester Food Ordering System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-12929 HIGH
SourceCodester Survey Application System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12928 HIGH
Code-projects Online Job Search Engine 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12927 MEDIUM
DedeBIZ < 6.3.2 - SQL Injection via archives_add.php flags[] Parameter
CVSS 4.7
CVE-2025-12926 MEDIUM
SourceCodester Farm Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-12865 HIGH
U-Office Force < 29.50 - Authenticated SQL Injection
CVSS 8.8
CVE-2025-12864 HIGH
U-Office Force < 29.50 - Authenticated SQL Injection
CVSS 8.8
CVE-2025-12914 MEDIUM
aaPanel BaoTa <=11.2.x - SQL Injection
CVSS 4.7
CVE-2025-12913 MEDIUM
Code-projects Responsive Hotel Site 1.0 - SQL Injection
CVSS 4.7
CVE-2025-11980 MEDIUM
Quick Featured Images <13.7.3 - SQL Injection
CVSS 4.9
CVE-2025-11972 MEDIUM
Tag, Category, Taxonomy Manager - AI Autotagger <3.40.0 - SQL Injec...
CVSS 4.9
CVE-2025-11452 HIGH
Asgaros Forum <3.1.0 - SQL Injection
CVSS 7.5
Details
Vulnerabilities 19,545
Exploit Likelihood High