CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 592 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-63878 | Med | 0.42 | 6.5 | 0.00 | Nov 19, 2025 | Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page. | ||
| CVE-2025-12646 | Hig | 0.42 | 7.5 | 0.00 | Nov 19, 2025 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | ||
| CVE-2025-63512 | Med | 0.42 | 6.5 | 0.00 | Nov 18, 2025 | kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or parameterize user-supplied input from the demail parameter before incorporating it directly into… | ||
| CVE-2024-44664 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php. | ||
| CVE-2024-44663 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php. | ||
| CVE-2024-44662 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page. | ||
| CVE-2024-44660 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php. | ||
| CVE-2024-44658 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php. | ||
| CVE-2024-44654 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset-password.php. | ||
| CVE-2024-44657 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in between-date-userreport.php. | ||
| CVE-2024-44653 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php. | ||
| CVE-2024-44651 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php. | ||
| CVE-2024-44652 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php. | ||
| CVE-2024-44648 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php. | ||
| CVE-2024-44644 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php. | ||
| CVE-2024-44641 | Med | 0.42 | 6.5 | 0.00 | Nov 17, 2025 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php. | ||
| CVE-2025-12482 | Hig | 0.42 | 7.5 | 0.00 | Nov 16, 2025 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient… | ||
| CVE-2024-55016 | Med | 0.42 | 6.5 | 0.00 | Nov 14, 2025 | PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php. | ||
| CVE-2024-44640 | Med | 0.42 | 6.5 | 0.00 | Nov 14, 2025 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php. | ||
| CVE-2024-44639 | Med | 0.42 | 6.5 | 0.00 | Nov 14, 2025 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php. |
- risk 0.42cvss 6.5epss 0.00
Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page.
- risk 0.42cvss 7.5epss 0.00
The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
- risk 0.42cvss 6.5epss 0.00
kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or parameterize user-supplied input from the demail parameter before incorporating it directly into…
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php.
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset-password.php.
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in between-date-userreport.php.
- risk 0.42cvss 6.5epss 0.00
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.
- risk 0.42cvss 6.5epss 0.00
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php.
- risk 0.42cvss 6.5epss 0.00
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php.
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.
- risk 0.42cvss 7.5epss 0.00
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient…
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php.
- risk 0.42cvss 6.5epss 0.00
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php.