CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,572 vulnerabilities with CWE-89
CVE-2025-11588 MEDIUM
CodeAstro Gym Management System 1.0 - SQL Injection via fullname Parameter
CVSS 6.3
CVE-2025-11585 HIGH
Project Monitoring System 1.0 - SQL Injection via uid Parameter in useredit.php
CVSS 7.3
CVE-2025-11584 HIGH
Online Job Search Engine 1.0 - SQL Injection via txtspecialization Parameter
CVSS 7.3
CVE-2025-11583 HIGH
Online Job Search Engine 1.0 - SQL Injection via txtjobID Parameter
CVSS 7.3
CVE-2025-11582 HIGH
Online Job Search Engine 1.0 - SQL Injection via txtusername Parameter
CVSS 7.3
CVE-2025-60269 CRITICAL
JEEWMS 20250820 - SQL Injection in exportXls Function
CVSS 9.4
CVE-2025-60307 CRITICAL
Computer Laboratory System 1.0 - SQL Injection
CVSS 9.8
CVE-2025-11188 HIGH
Kiwire Captive Portal - SQL Injection
CVSS 7.3
CVE-2025-11558 HIGH
code-projects E-Commerce Website 1.0 - SQL Injection via Search Parameter
CVSS 7.3
CVE-2025-11557 HIGH
projectworlds Gate Pass Management System 1.0 - SQL Injection via fullname Parameter in add-pass.php
CVSS 7.3
CVE-2025-11556 HIGH
Simple Leave Manager 1.0 - SQL Injection via User.php Table Parameter
CVSS 7.3
CVE-2025-11555 HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via date_start Parameter
CVSS 7.3
CVE-2025-60316 CRITICAL
SourceCodester Pet Grooming <1.0 - SQL Injection
CVSS 9.4
CVE-2025-11553 MEDIUM
Courier Management System 1.0 - SQL Injection via Shippername Parameter
CVSS 6.3
CVE-2025-11552 MEDIUM
Online Complaint Site 1.0 - SQL Injection via Category Argument in /admin/category.php
CVSS 6.3
CVE-2025-60267 MEDIUM
xckk v9.6 - SQL Injection via Notice List Cond Parameter
CVSS 6.5
CVE-2025-11551 MEDIUM
Student Result Manager 1.0 - SQL Injection via Roll/Name/GPA Argument
CVSS 6.3
CVE-2025-60266 MEDIUM
xckk v9.6 - SQL Injection via address/list orderBy Parameter
CVSS 6.5
CVE-2025-60265 MEDIUM
xckk v9.6 - SQL Injection via user/list orderBy Parameter
CVSS 6.5
CVE-2025-62228 HIGH
Apache Flink CDC 3.4.0 - Authenticated SQL Injection via Maliciously Crafted Identifiers
CVSS 8.8
CVE-2025-10862 HIGH
Popup builder with Gamification, Multi-Step Popups, Page-Level Targ...
CVSS 7.5
CVE-2025-11530 MEDIUM
Online Complaint Site 1.0 - SQL Injection via state Parameter in /cms/admin/state.php
CVSS 6.3
CVE-2025-10586 CRITICAL
Community Events <1.5.1 - SQL Injection
CVSS 9.8
CVE-2025-11516 MEDIUM
Online Complaint Site 1.0 - SQL Injection via cid Parameter
CVSS 6.3
CVE-2025-11515 MEDIUM
Online Complaint Site 1.0 - SQL Injection via Register Complaint CID Parameter
CVSS 6.3
Details
Vulnerabilities 19,572
Exploit Likelihood High