CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,487
Total CVEs
1,926
Critical
1,910
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
241
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 126
2 Oretnom23 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,487)

CVE-2024-42558
9.8

This SQL injection vulnerability in Hotel Management System allows attackers to execute arbitrary SQL commands through the book_id parameter in admin_...

Aug 20, 2024
CVE-2024-6847
9.8

This SQL injection vulnerability in the Chatbot with ChatGPT WordPress plugin allows unauthenticated attackers to execute arbitrary SQL commands by su...

Aug 20, 2024
CVE-2024-42843
9.8

CVE-2024-42843 is a critical SQL injection vulnerability in Projectworlds Online Examination System v1.0 that allows attackers to execute arbitrary SQ...

Aug 15, 2024
CVE-2024-7731
9.8

This critical SQL injection vulnerability in Dr.ID Access Control System allows unauthenticated attackers to execute arbitrary SQL commands remotely. ...

Aug 14, 2024
CVE-2024-43360
9.8

ZoneMinder CCTV software contains a time-based SQL injection vulnerability (CWE-89) that allows attackers to execute arbitrary SQL commands by manipul...

Aug 12, 2024
CVE-2024-40486
9.8

A SQL injection vulnerability in Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands via the email or pass...

Aug 12, 2024
CVE-2024-40477
9.8

This SQL injection vulnerability in PHPGurukul Old Age Home Management System allows attackers to execute arbitrary SQL commands through the forgot pa...

Aug 12, 2024
CVE-2024-41237
9.8

This SQL injection vulnerability in Kashipara Responsive School Management System allows attackers to execute arbitrary SQL commands through the teach...

Aug 7, 2024
CVE-2024-34479
9.8

This vulnerability allows SQL injection through the id parameter in classes/Master.php in SourceCodester Computer Laboratory Management System 1.0. At...

Aug 7, 2024
CVE-2024-33974
9.8

This SQL injection vulnerability in Janobe products allows attackers to execute arbitrary SQL queries through the 'Users' parameter in '/report/printl...

Aug 6, 2024
CVE-2024-33970
9.8

A critical SQL injection vulnerability in the PayPal, Credit Card and Debit Card Payment module allows attackers to execute arbitrary SQL queries thro...

Aug 6, 2024
CVE-2024-33972
9.8

A critical SQL injection vulnerability in Janobe products' payment module allows attackers to execute arbitrary SQL queries through the '/report/event...

Aug 6, 2024
CVE-2024-33964
9.8

A critical SQL injection vulnerability exists in the PayPal, Credit Card and Debit Card Payment module version 1.0, allowing attackers to execute arbi...

Aug 6, 2024
CVE-2024-33966
9.8

This is a critical SQL injection vulnerability in the payment module affecting version 1.0 of unspecified Janobe products. Attackers can exploit it to...

Aug 6, 2024
CVE-2024-33968
9.8

This SQL injection vulnerability in a payment module allows attackers to execute arbitrary SQL queries through the 'Attendance' and 'YearLevel' parame...

Aug 6, 2024
CVE-2024-33960
9.8

This is a critical SQL injection vulnerability in a payment processing component that allows attackers to execute arbitrary SQL queries. Attackers can...

Aug 6, 2024
CVE-2024-33962
9.8

This CVE describes a critical SQL injection vulnerability in a payment module, allowing attackers to execute arbitrary SQL queries via a crafted 'code...

Aug 6, 2024
CVE-2024-33959
9.8

This SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment version 1.0 allows attackers to execute arbitrary SQL queries through t...

Aug 6, 2024
CVE-2024-33957
9.8

This SQL injection vulnerability in E-Negosyo System version 1.0 allows attackers to execute arbitrary SQL commands through the '/admin/orders/control...

Aug 6, 2024
CVE-2024-40498
9.8

This SQL injection vulnerability in PuneethReddyHC Online Shopping System Advanced v1.0 allows attackers to execute arbitrary SQL commands through the...

Aug 5, 2024
CVE-2024-38889
9.8

This SQL injection vulnerability in Caterease software allows remote attackers to execute arbitrary SQL commands on affected systems. All organization...

Aug 2, 2024
CVE-2024-6699
9.8

This SQL injection vulnerability in Mikafon MA7 devices allows attackers to execute arbitrary SQL commands on the database. It affects Mikafon MA7 dev...

Jul 30, 2024
CVE-2024-41702
9.8

This SQL injection vulnerability in SiberianCMS allows attackers to execute arbitrary SQL commands on the database. It affects all SiberianCMS install...

Jul 30, 2024
CVE-2024-5765
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the WpStickyBar plugin. Attackers can p...

Jul 30, 2024
CVE-2024-37858
9.8

This SQL injection vulnerability in Lost and Found Information System 1.0 allows remote attackers to execute arbitrary SQL commands via the id paramet...

Jul 29, 2024
CVE-2024-7202
9.8

CVE-2024-7202 is a critical SQL injection vulnerability in Simopro Technology's WinMatrix3 Web package that allows unauthenticated remote attackers to...

Jul 29, 2024
CVE-2024-7201
9.8

CVE-2024-7201 is a critical SQL injection vulnerability in the WinMatrix3 Web package from Simopro Technology. Unauthenticated remote attackers can ex...

Jul 29, 2024
CVE-2024-38289
9.8

This is a critical SQL injection vulnerability in R-HUB TurboMeeting's Virtual Meeting Password endpoint that allows unauthenticated remote attackers ...

Jul 25, 2024
CVE-2024-41551
9.8

CampCodes Supplier Management System v1.0 contains a SQL injection vulnerability in the admin view_order_items.php endpoint that allows attackers to e...

Jul 24, 2024
CVE-2024-40502
9.8

This SQL injection vulnerability in the Hospital Management System Project in ASP.Net MVC allows remote attackers to execute arbitrary SQL commands vi...

Jul 22, 2024
CVE-2024-39250
9.8

CVE-2024-39250 is an unauthenticated SQL injection vulnerability in EfroTech Timetrax v8.3 that allows attackers to execute arbitrary SQL commands via...

Jul 22, 2024
CVE-2024-6205
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the PayPlus Payment Gateway plugin befo...

Jul 19, 2024
CVE-2024-0857
9.8

This SQL injection vulnerability in Universal Software Inc.'s FlexWater Corporate Water Management allows attackers to execute arbitrary SQL commands ...

Jul 18, 2024
CVE-2024-39907
9.8

CVE-2024-39907 is a critical SQL injection vulnerability in 1Panel, a web-based Linux server management control panel. The vulnerability allows attack...

Jul 18, 2024
CVE-2024-40456
9.8

ThinkSAAS v3.7.0 contains a SQL injection vulnerability in the name parameter at \system\action\update.php. This allows attackers to execute arbitrary...

Jul 16, 2024
CVE-2024-40392
9.8

This CVE describes a SQL injection vulnerability in the Pharmacy/Medical Store Point of Sale System version 1.0. Attackers can inject malicious SQL co...

Jul 16, 2024
CVE-2024-6457
9.8

This vulnerability allows unauthenticated attackers to perform time-based SQL injection attacks through the 'woof_author' parameter in the HUSKY – P...

Jul 16, 2024
CVE-2024-6743
9.8

This critical SQL injection vulnerability in AguardNet's Space Management System allows unauthenticated remote attackers to execute arbitrary SQL comm...

Jul 15, 2024
CVE-2024-40539
9.8

This SQL injection vulnerability in my-springsecurity-plus allows attackers to execute arbitrary SQL commands through the dataScope parameter in the /...

Jul 12, 2024
CVE-2024-40541
9.8

This SQL injection vulnerability in my-springsecurity-plus allows attackers to execute arbitrary SQL commands via the dataScope parameter in the /api/...

Jul 12, 2024
CVE-2024-37873
9.8

This SQL injection vulnerability in the Itsourcecode Payroll Management System allows remote attackers to execute arbitrary SQL commands through the i...

Jul 9, 2024
CVE-2024-37870
9.8

This CVE describes a critical SQL injection vulnerability in the Learning Management System Project In PHP With Source Code 1.0. Attackers can execute...

Jul 9, 2024
CVE-2024-40614
9.8

This vulnerability allows authenticated users to perform SQL injection attacks through the Address Book or InfoLog sorting functionality in EGroupware...

Jul 7, 2024
CVE-2024-27709
9.8

This SQL injection vulnerability in Eskooly Web Product v3.0 allows remote attackers to execute arbitrary SQL commands via the searchby parameter in a...

Jul 5, 2024
CVE-2024-6265
9.8

This vulnerability allows unauthenticated attackers to perform time-based SQL injection attacks on WordPress sites using the UsersWP plugin. Attackers...

Jun 29, 2024
CVE-2024-5827
9.8

CVE-2024-5827 is a critical SQL injection vulnerability in Vanna v0.3.4's DuckDB integration that allows attackers to write arbitrary files to the ser...

Jun 28, 2024
CVE-2024-3816
9.8

This CVE describes a blind SQL injection vulnerability in S@M CMS (Concept Intermedia) search functionality. Attackers can execute arbitrary SQL queri...

Jun 28, 2024
CVE-2024-4228
9.8

This SQL injection vulnerability in Magarsus Consultancy SSO allows attackers to execute arbitrary SQL commands. It affects all versions from 1.0 befo...

Jun 26, 2024
CVE-2024-37843
9.8

CVE-2024-37843 is an unauthenticated SQL injection vulnerability in Craft CMS's GraphQL API endpoint. Attackers can execute arbitrary SQL commands wit...

Jun 25, 2024
CVE-2024-6028
9.8

The Quiz Maker WordPress plugin contains a time-based SQL injection vulnerability in the 'ays_questions' parameter that allows unauthenticated attacke...

Jun 25, 2024

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,487 CVEs classified as CWE-89, with 1,926 rated critical and 1,910 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free