CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,572 vulnerabilities with CWE-89
CVE-2025-11588
MEDIUM
CodeAstro Gym Management System 1.0 - SQL Injection via fullname Parameter
CVSS 6.3
CVE-2025-11585
HIGH
Project Monitoring System 1.0 - SQL Injection via uid Parameter in useredit.php
CVSS 7.3
CVE-2025-11584
HIGH
Online Job Search Engine 1.0 - SQL Injection via txtspecialization Parameter
CVSS 7.3
CVE-2025-11583
HIGH
Online Job Search Engine 1.0 - SQL Injection via txtjobID Parameter
CVSS 7.3
CVE-2025-11582
HIGH
Online Job Search Engine 1.0 - SQL Injection via txtusername Parameter
CVSS 7.3
CVE-2025-60269
CRITICAL
JEEWMS 20250820 - SQL Injection in exportXls Function
CVSS 9.4
CVE-2025-60307
CRITICAL
Computer Laboratory System 1.0 - SQL Injection
CVSS 9.8
CVE-2025-11188
HIGH
Kiwire Captive Portal - SQL Injection
CVSS 7.3
CVE-2025-11558
HIGH
code-projects E-Commerce Website 1.0 - SQL Injection via Search Parameter
CVSS 7.3
CVE-2025-11557
HIGH
projectworlds Gate Pass Management System 1.0 - SQL Injection via fullname Parameter in add-pass.php
CVSS 7.3
CVE-2025-11556
HIGH
Simple Leave Manager 1.0 - SQL Injection via User.php Table Parameter
CVSS 7.3
CVE-2025-11555
HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via date_start Parameter
CVSS 7.3
CVE-2025-60316
CRITICAL
SourceCodester Pet Grooming <1.0 - SQL Injection
CVSS 9.4
CVE-2025-11553
MEDIUM
Courier Management System 1.0 - SQL Injection via Shippername Parameter
CVSS 6.3
CVE-2025-11552
MEDIUM
Online Complaint Site 1.0 - SQL Injection via Category Argument in /admin/category.php
CVSS 6.3
CVE-2025-60267
MEDIUM
xckk v9.6 - SQL Injection via Notice List Cond Parameter
CVSS 6.5
CVE-2025-11551
MEDIUM
Student Result Manager 1.0 - SQL Injection via Roll/Name/GPA Argument
CVSS 6.3
CVE-2025-60266
MEDIUM
xckk v9.6 - SQL Injection via address/list orderBy Parameter
CVSS 6.5
CVE-2025-60265
MEDIUM
xckk v9.6 - SQL Injection via user/list orderBy Parameter
CVSS 6.5
CVE-2025-62228
HIGH
Apache Flink CDC 3.4.0 - Authenticated SQL Injection via Maliciously Crafted Identifiers
CVSS 8.8
CVE-2025-10862
HIGH
Popup builder with Gamification, Multi-Step Popups, Page-Level Targ...
CVSS 7.5
CVE-2025-11530
MEDIUM
Online Complaint Site 1.0 - SQL Injection via state Parameter in /cms/admin/state.php
CVSS 6.3
CVE-2025-10586
CRITICAL
Community Events <1.5.1 - SQL Injection
CVSS 9.8
CVE-2025-11516
MEDIUM
Online Complaint Site 1.0 - SQL Injection via cid Parameter
CVSS 6.3
CVE-2025-11515
MEDIUM
Online Complaint Site 1.0 - SQL Injection via Register Complaint CID Parameter
CVSS 6.3
Details
Vulnerabilities
19,572
Exploit Likelihood
High