CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,567 vulnerabilities with CWE-89
CVE-2025-11740
MEDIUM
wpForo Forum <2.4.9 - SQL Injection
CVSS 6.5
CVE-2025-64366
HIGH
Stylemix MasterStudy LMS <= 3.6.27 - SQL Injection
CVSS 7.6
CVE-2025-6520
CRITICAL
Abis Technology BAPSIS <202510271606 - SQL Injection
CVSS 9.8
CVE-2025-52664
HIGH
Revive Adserver 6.0.0 - Authenticated SQL Injection
CVSS 8.8
CVE-2025-63608
MEDIUM
CSZ-CMS <= 1.3.0 - Authenticated SQL Injection via Form Builder Field Parameter
CVSS 5.4
CVE-2025-64104
HIGH
langgraph-checkpoint-sqlite < 2.0.11 - SQL Injection via Improper String Concatenation
CVSS 7.3
CVE-2025-60542
MEDIUM
TypeORM < 0.3.26 - SQL Injection via repository.save or repository.update
CVSS 6.5
CVE-2025-63622
CRITICAL
code-projects Online Complaint Site 1.0 - SQL Injection
CVSS 9.8
CVE-2025-4665
CRITICAL
WordPress plugin Contact Form CFDB7 <1.3.2 - SQL Injection
CVSS 9.6
CVE-2025-62367
MEDIUM
taiga-back < 6.9.0 - Time-Based Blind SQL Injection via Response Timing
CVSS 4.8
CVE-2025-34304
MEDIUM
IPFire < 2.29 - Authenticated SQL Injection via OpenVPN Connection Logs CONNECTION_NAME Parameter
CVSS 6.5
CVE-2025-11735
HIGH
HUSKY - Products Filter Professional - SQL Injection
CVSS 7.5
CVE-2025-12342
HIGH
Serdar Bayram Ghost Hot Spot <20251014 - SQL Injection
CVSS 7.3
CVE-2025-12339
HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via /admin/admin_football.php pid Parameter
CVSS 7.3
CVE-2025-12338
HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via /admin/admin_product.php pid Parameter
CVSS 7.3
CVE-2025-12337
HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via admin_feature.php pid Parameter
CVSS 7.3
CVE-2025-12336
HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-12329
MEDIUM
shawonruet/ruet_oj < 2022-10-19 - SQL Injection via ID Parameter in /details.php
CVSS 6.3
CVE-2025-12328
MEDIUM
shawonruet/ruet_oj < 2022-10-19 - SQL Injection via Name Argument in contestproblem.php
CVSS 6.3
CVE-2025-12327
MEDIUM
shawonruet/ruet_oj < 2022-10-19 - SQL Injection via ID Parameter in /description.php
CVSS 6.3
CVE-2025-12326
HIGH
shawonruet/ruet_oj < 2022-10-19 - SQL Injection via POST Request Handler
CVSS 7.3
CVE-2025-12325
HIGH
Best Salon Management System 1.0 - SQL Injection via Forgot Password Email Parameter
CVSS 7.3
CVE-2025-12316
HIGH
Courier Management System 1.0 - SQL Injection via OfficeName Parameter in Edit Courier
CVSS 7.3
CVE-2025-12315
MEDIUM
Food Ordering System 1.0 - SQL Injection via itemPrice Parameter in /admin/menu.php
CVSS 4.7
CVE-2025-12314
MEDIUM
code-projects Food Ordering System 1.0 - SQL Injection via /admin/deleteitem.php itemID Parameter
CVSS 4.7
Details
Vulnerabilities
19,567
Exploit Likelihood
High