CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,567 vulnerabilities with CWE-89
CVE-2025-10683 MEDIUM
Easy Email Subscription <1.3 - SQL Injection
CVSS 4.9
CVE-2025-64114 MEDIUM
ClipBucket 5.3-5.5.2-151 - Authenticated SQL Injection via Custom Fields Plugin
CVSS 6.5
CVE-2025-63585 MEDIUM
Open Source Social Network 8.6 - SQL Injection via Timestamp Parameter
CVSS 6.5
CVE-2025-55343 CRITICAL
Quipux 4.0.1-e1774ac - SQL Injection
CVSS 9.9
CVE-2025-64459 CRITICAL
Django 4.2-4.2.25 5.1-5.1.13 5.2a1-5.2.7 - SQL Injection via QuerySet Dictionary Expansion
CVSS 9.1
CVE-2025-12197 HIGH
The Events Calendar <6.15.9 - SQL Injection
CVSS 7.5
CVE-2025-32786 HIGH
GLPI Inventory Plugin <1.5.1 - SQL Injection
CVSS 7.5
CVE-2025-12463 CRITICAL
Geutebruck G-Cam E-Series - SQL Injection
CVSS 9.8
CVE-2025-63453 CRITICAL
Car-Booking-System-PHP v.1.0 - SQL Injection
CVSS 9.8
CVE-2025-63452 CRITICAL
Car-Booking-System-PHP <1.0 - SQL Injection
CVSS 9.4
CVE-2025-63451 CRITICAL
Car-Booking-System-PHP v.1.0 - SQL Injection
CVSS 9.8
CVE-2025-12503 MEDIUM
EasyFlow .NET/AiNet - SQL Injection
CVSS 6.5
CVE-2025-12617 HIGH
itsourcecode Billing System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12614 MEDIUM
SourceCodester Best House Rental Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12612 MEDIUM
Campcodes School Fees Payment Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-12610 MEDIUM
CodeAstro Gym Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12609 MEDIUM
CodeAstro Gym Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12608 HIGH
iSourcecode Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12607 HIGH
isourcecode Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12606 HIGH
iSourcecode Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12605 HIGH
itsourcecode Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12604 HIGH
itsourcecode Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12598 MEDIUM
SourceCodester Best House Rental Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12597 MEDIUM
SourceCodester Best House Rental Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12594 MEDIUM
Simple Online Hotel Reservation System 2.0 - SQL Injection
CVSS 4.7
Details
Vulnerabilities 19,567
Exploit Likelihood High