CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,572 vulnerabilities with CWE-89
CVE-2025-11434 HIGH
itsourcecode Student Transcript Processing System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11432 HIGH
itsourcecode Leave Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11204 HIGH
RegistrationMagic <6.0.6.2 - SQL Injection
CVSS 7.2
CVE-2025-11431 MEDIUM
Code-projects Web-Based Inventory & POS System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11430 HIGH
SourceCodester Simple E-Commerce Bookstore 1.0 - SQL Injection
CVSS 7.3
CVE-2025-10587 CRITICAL
WordPress Community Events <1.5.1 - SQL Injection
CVSS 9.8
CVE-2025-11424 HIGH
Code-projects Web-Based Inventory & POS System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11422 HIGH
Campcodes Advanced Online Voting Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11420 HIGH
code-projects E-Commerce Website 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11416 HIGH
PHPGurukul Beauty Parlour Management System 1.1 - SQL Injection
CVSS 7.3
CVE-2025-11415 HIGH
PHPGurukul Beauty Parlour Management System 1.1 - SQL Injection
CVSS 7.3
CVE-2025-11410 MEDIUM
Campcodes Advanced Online Voting Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11409 MEDIUM
Campcodes AOVMS 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11405 MEDIUM
SourceCodester Hotel and Lodge Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11404 MEDIUM
SourceCodester Hotel and Lodge Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11403 MEDIUM
SourceCodester Hotel and Lodge Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11402 MEDIUM
SourceCodester Hotel and Lodge Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-52021 CRITICAL
PuneethReddyHC Online Shopping System Advanced 1.0 - SQL Injection
CVSS 9.8
CVE-2025-11401 MEDIUM
SourceCodester Hotel and Lodge Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11400 MEDIUM
SourceCodester Hotel and Lodge Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11399 MEDIUM
SourceCodester Hotel and Lodge Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11397 HIGH
SourceCodester Hotel and Lodge Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-40888 MEDIUM
Nozomi Networks CMC and Guardian < 25.3.0 - Authenticated SQL Injection via CLI Input Parameter
CVSS 5.3
CVE-2025-40887 MEDIUM
Nozomi Networks CMC and Guardian < 25.2.0 - Authenticated SQL Injection via Alert Input Parameter
CVSS 5.3
CVE-2025-40886 HIGH
Nozomi Networks CMC and Guardian < 25.2.0 - Authenticated SQL Injection via Alert Input Parameter
CVSS 7.5
Details
Vulnerabilities 19,572
Exploit Likelihood High