CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,444
Total CVEs
1,899
Critical
1,894
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
241
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Oretnom23 125
2 Phpgurukul 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,444)

CVE-2025-10878
10.0

An unauthenticated SQL injection vulnerability in Fikir Odalari AdminPando 1.0.1 allows attackers to bypass authentication completely. Successful expl...

Feb 3, 2026
CVE-2025-57792
10.0

CVE-2025-57792 is a critical SQL injection vulnerability in Explorance Blue software that allows unauthenticated attackers to execute arbitrary SQL co...

Jan 28, 2026
CVE-2025-52694
10.0

This critical SQL injection vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on internet-exposed services. Successful ...

Jan 12, 2026
CVE-2025-63531
10.0

This SQL injection vulnerability in Blood Bank Management System 1.0 allows attackers to bypass authentication by injecting malicious SQL code through...

Dec 1, 2025
CVE-2025-63689
10.0

Multiple SQL injection vulnerabilities in the ycf1998 money-pos system allow remote attackers to execute arbitrary SQL commands via the orderby parame...

Nov 7, 2025
CVE-2025-50567
10.0

Saurus CMS Community Edition 4.7.1 contains a critical SQL injection vulnerability in the DB::prepare() function due to improper use of preg_replace()...

Aug 19, 2025
CVE-2025-54119
10.0

This SQL injection vulnerability in ADOdb allows attackers to execute arbitrary SQL commands when applications connect to SQLite3 databases and call m...

Aug 5, 2025
CVE-2025-4285
10.0

This SQL injection vulnerability in Rolantis Agentis allows attackers to execute arbitrary SQL commands through unvalidated user input. It affects all...

Jul 22, 2025
CVE-2025-46337
10.0

This is a critical SQL injection vulnerability in ADOdb PHP database library affecting PostgreSQL connections. Attackers can execute arbitrary SQL sta...

May 1, 2025
CVE-2025-26852
10.0

DESCOR INFOCAD versions 3.5.1 and earlier contain a SQL injection vulnerability that allows attackers to execute arbitrary SQL commands on the databas...

Mar 20, 2025
CVE-2025-22954
EPSS 11.9% 10.0

This SQL injection vulnerability in Koha library management software allows attackers to execute arbitrary SQL commands via the supplierid or serialid...

Mar 12, 2025
CVE-2024-13152
10.0

This SQL injection vulnerability in BSS Software's Mobuy Online Machinery Monitoring Panel allows attackers to execute arbitrary SQL commands on the d...

Feb 14, 2025
CVE-2024-54261
10.0

This SQL injection vulnerability in the TAX SERVICE Electronic HDM WordPress plugin allows attackers to execute arbitrary SQL commands on the database...

Dec 13, 2024
CVE-2024-8522
10.0

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites using the LearnPress plugin. Attackers can ext...

Sep 12, 2024
CVE-2024-7854
10.0

The Woo Inquiry WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries. This ...

Aug 21, 2024
CVE-2024-37112
10.0

This is an unauthenticated SQL injection vulnerability in the WordPress WishList Member X plugin. Attackers can execute arbitrary SQL queries on affec...

Jul 9, 2024
CVE-2024-3605
10.0

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites using the WP Hotel Booking plugin. By manipula...

Jun 20, 2024
CVE-2024-3922
10.0

The Dokan Pro WordPress plugin contains an unauthenticated SQL injection vulnerability in the 'code' parameter. Attackers can exploit this to execute ...

Jun 13, 2024
CVE-2024-36412
10.0

This is a critical SQL injection vulnerability in SuiteCRM that allows attackers to execute arbitrary SQL commands through the events response entry p...

Jun 10, 2024
CVE-2024-32888
10.0

This CVE describes a SQL injection vulnerability in the Amazon JDBC Driver for Redshift when using the unsupported 'preferQueryMode=simple' connection...

May 15, 2024
CVE-2024-27298
10.0

This SQL injection vulnerability in parse-server allows attackers to execute arbitrary SQL commands when the server is configured with PostgreSQL. It ...

Mar 1, 2024
CVE-2024-1597
10.0

This SQL injection vulnerability in the PostgreSQL JDBC Driver (pgjdbc) allows attackers to bypass parameterized query protections when using PreferQu...

Feb 19, 2024
CVE-2023-34976
10.0

This SQL injection vulnerability in QNAP Video Station allows authenticated attackers to execute arbitrary SQL commands via network requests. It affec...

Oct 13, 2023
CVE-2023-4309
10.0

Election Services Co. Internet Election Service has multiple SQL injection vulnerabilities that allow unauthenticated remote attackers to read or modi...

Oct 10, 2023
CVE-2023-39344
10.0

This CVE describes a critical SQL injection vulnerability in the social-media-skeleton project that allows UNION-based injections, which can lead to r...

Aug 4, 2023
CVE-2023-25813
10.0

CVE-2023-25813 is a critical SQL injection vulnerability in Sequelize ORM for Node.js where user-provided parameters passed through replacements are n...

Feb 22, 2023
CVE-2022-2421
10.0

CVE-2022-2421 is a critical vulnerability in the Socket.io JavaScript library that allows attackers to inject malicious function references into query...

Oct 26, 2022
CVE-2021-27472
10.0

This vulnerability allows unauthenticated remote attackers to execute arbitrary SQL statements against Rockwell Automation FactoryTalk AssetCentre dat...

Mar 23, 2022
CVE-2021-27464
10.0

This critical vulnerability in Rockwell Automation FactoryTalk AssetCentre allows remote, unauthenticated attackers to execute arbitrary SQL statement...

Mar 23, 2022
CVE-2021-27468
10.0

This critical vulnerability in Rockwell Automation FactoryTalk AssetCentre allows remote, unauthenticated attackers to execute arbitrary SQL statement...

Mar 23, 2022
CVE-2022-21643
10.0

CVE-2022-21643 is a critical SQL injection vulnerability in USOC CMS that allows attackers to execute arbitrary SQL commands through the registration ...

Jan 4, 2022
CVE-2021-42311
10.0

CVE-2021-42311 is a critical SQL injection vulnerability in Microsoft Defender for IoT that allows remote attackers to execute arbitrary code on affec...

Dec 15, 2021
CVE-2021-42313
10.0

CVE-2021-42313 is a critical SQL injection vulnerability in Microsoft Defender for IoT that allows remote attackers to execute arbitrary code on affec...

Dec 15, 2021
CVE-2020-29493
10.0

This critical SQL injection vulnerability in Dell EMC Avamar Server's Fitness Analyzer allows remote unauthenticated attackers to execute arbitrary SQ...

Jan 14, 2021
CVE-2026-24908
9.9

OpenEMR versions before 8.0.0 contain an SQL injection vulnerability in the Patient REST API endpoint that allows authenticated users with API access ...

Feb 25, 2026
CVE-2025-24290
9.9

Multiple authenticated SQL injection vulnerabilities in UISP Application version 2.4.206 and earlier allow attackers with low-privilege accounts to ex...

Jun 29, 2025
CVE-2024-45387
9.9

An SQL injection vulnerability in Apache Traffic Control's Traffic Ops component allows authenticated users with specific privileged roles (admin, fed...

Dec 23, 2024
CVE-2024-42327
9.9

This CVE describes an SQL injection vulnerability in Zabbix's CUser class that allows non-admin users with API access to execute arbitrary SQL queries...

Nov 27, 2024
CVE-2024-51482
9.9

ZoneMinder versions 1.37.64 and earlier contain a boolean-based SQL injection vulnerability in the event.php component. This allows attackers to execu...

Oct 31, 2024
CVE-2024-8621
9.9

This SQL injection vulnerability in the Daily Prayer Time WordPress plugin allows authenticated attackers with Contributor-level access or higher to e...

Sep 25, 2024
CVE-2024-8436
9.9

This SQL injection vulnerability in the WP Easy Gallery WordPress plugin allows authenticated attackers with subscriber-level access or higher to exec...

Sep 25, 2024
CVE-2024-8624
9.9

This SQL injection vulnerability in the MDTF WordPress plugin allows authenticated attackers with Contributor-level access or higher to inject malicio...

Sep 24, 2024
CVE-2024-3604
9.9

This SQL injection vulnerability in the OSM OpenStreetMap WordPress plugin allows authenticated attackers with contributor-level access or higher to i...

Jul 9, 2024
CVE-2024-3549
9.9

This SQL injection vulnerability in the Blog2Social WordPress plugin allows authenticated attackers with subscriber-level access or higher to inject m...

Jun 11, 2024
CVE-2024-3592
9.9

This SQL injection vulnerability in the Quiz And Survey Master WordPress plugin allows authenticated attackers with contributor-level access or higher...

Jun 7, 2024
CVE-2024-36393
9.9

This SQL injection vulnerability in SysAid allows attackers to execute arbitrary SQL commands on the database. It affects organizations using vulnerab...

Jun 6, 2024
CVE-2024-3200
9.9

This SQL injection vulnerability in the wpForo Forum WordPress plugin allows authenticated attackers with contributor-level access or higher to inject...

Jun 1, 2024
CVE-2024-27956
9.9

This CVE describes an unauthenticated SQL injection vulnerability in the WordPress Automatic plugin (ValvePress Automatic). Attackers can execute arbi...

Mar 21, 2024
CVE-2021-43609
9.9

This is a critical SQL injection vulnerability in Spiceworks Help Desk Server that allows authenticated attackers to execute arbitrary SQL commands vi...

Nov 9, 2023
CVE-2023-45162
9.9

CVE-2023-45162 is a blind SQL injection vulnerability in 1E Platform that allows attackers to execute arbitrary SQL commands, potentially leading to r...

Oct 13, 2023

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,444 CVEs classified as CWE-89, with 1,899 rated critical and 1,894 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free