CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,567 vulnerabilities with CWE-89
CVE-2025-11740 MEDIUM
wpForo Forum <2.4.9 - SQL Injection
CVSS 6.5
CVE-2025-64366 HIGH
Stylemix MasterStudy LMS <= 3.6.27 - SQL Injection
CVSS 7.6
CVE-2025-6520 CRITICAL
Abis Technology BAPSIS <202510271606 - SQL Injection
CVSS 9.8
CVE-2025-52664 HIGH
Revive Adserver 6.0.0 - Authenticated SQL Injection
CVSS 8.8
CVE-2025-63608 MEDIUM
CSZ-CMS <= 1.3.0 - Authenticated SQL Injection via Form Builder Field Parameter
CVSS 5.4
CVE-2025-64104 HIGH
langgraph-checkpoint-sqlite < 2.0.11 - SQL Injection via Improper String Concatenation
CVSS 7.3
CVE-2025-60542 MEDIUM
TypeORM < 0.3.26 - SQL Injection via repository.save or repository.update
CVSS 6.5
CVE-2025-63622 CRITICAL
code-projects Online Complaint Site 1.0 - SQL Injection
CVSS 9.8
CVE-2025-4665 CRITICAL
WordPress plugin Contact Form CFDB7 <1.3.2 - SQL Injection
CVSS 9.6
CVE-2025-62367 MEDIUM
taiga-back < 6.9.0 - Time-Based Blind SQL Injection via Response Timing
CVSS 4.8
CVE-2025-34304 MEDIUM
IPFire < 2.29 - Authenticated SQL Injection via OpenVPN Connection Logs CONNECTION_NAME Parameter
CVSS 6.5
CVE-2025-11735 HIGH
HUSKY - Products Filter Professional - SQL Injection
CVSS 7.5
CVE-2025-12342 HIGH
Serdar Bayram Ghost Hot Spot <20251014 - SQL Injection
CVSS 7.3
CVE-2025-12339 HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via /admin/admin_football.php pid Parameter
CVSS 7.3
CVE-2025-12338 HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via /admin/admin_product.php pid Parameter
CVSS 7.3
CVE-2025-12337 HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via admin_feature.php pid Parameter
CVSS 7.3
CVE-2025-12336 HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-12329 MEDIUM
shawonruet/ruet_oj < 2022-10-19 - SQL Injection via ID Parameter in /details.php
CVSS 6.3
CVE-2025-12328 MEDIUM
shawonruet/ruet_oj < 2022-10-19 - SQL Injection via Name Argument in contestproblem.php
CVSS 6.3
CVE-2025-12327 MEDIUM
shawonruet/ruet_oj < 2022-10-19 - SQL Injection via ID Parameter in /description.php
CVSS 6.3
CVE-2025-12326 HIGH
shawonruet/ruet_oj < 2022-10-19 - SQL Injection via POST Request Handler
CVSS 7.3
CVE-2025-12325 HIGH
Best Salon Management System 1.0 - SQL Injection via Forgot Password Email Parameter
CVSS 7.3
CVE-2025-12316 HIGH
Courier Management System 1.0 - SQL Injection via OfficeName Parameter in Edit Courier
CVSS 7.3
CVE-2025-12315 MEDIUM
Food Ordering System 1.0 - SQL Injection via itemPrice Parameter in /admin/menu.php
CVSS 4.7
CVE-2025-12314 MEDIUM
code-projects Food Ordering System 1.0 - SQL Injection via /admin/deleteitem.php itemID Parameter
CVSS 4.7
Details
Vulnerabilities 19,567
Exploit Likelihood High