CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,487
Total CVEs
1,926
Critical
1,910
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
241
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 126
2 Oretnom23 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,487)

CVE-2024-34988
9.8

This SQL injection vulnerability in the PrestaShop 'Complete for Create a Quote in Frontend + Backend Pro' module allows attackers to execute arbitrar...

Jun 24, 2024
CVE-2024-36681
9.8

This CVE describes a critical SQL injection vulnerability in the Isotope module for PrestaShop. Attackers can exploit the saveData and removeData meth...

Jun 24, 2024
CVE-2024-34989
9.8

This SQL injection vulnerability in the RSI PDF/HTML catalog evolution module for PrestaShop allows unauthenticated attackers to execute arbitrary SQL...

Jun 21, 2024
CVE-2024-6027
9.8

This vulnerability allows unauthenticated attackers to perform time-based SQL injection attacks on WordPress sites using the Themify WooCommerce Produ...

Jun 21, 2024
CVE-2024-5756
9.8

This vulnerability allows unauthenticated attackers to perform time-based SQL injection attacks against the Email Subscribers WordPress plugin. Attack...

Jun 21, 2024
CVE-2024-37699
9.8

CVE-2024-37699 is a critical SQL injection vulnerability in DataLife Engine's dboption component that allows attackers to execute arbitrary SQL comman...

Jun 20, 2024
CVE-2024-4742
9.8

This SQL injection vulnerability in the Youzify WordPress plugin allows authenticated attackers with Contributor-level access or higher to inject mali...

Jun 20, 2024
CVE-2024-34994
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on PrestaShop installations using the Channable module. It affec...

Jun 19, 2024
CVE-2024-36678
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries on PrestaShop installations using the vulnerable pk_themesettings...

Jun 19, 2024
CVE-2024-36684
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on PrestaShop websites using the 'Custom links' module (pk_custom...

Jun 19, 2024
CVE-2024-37831
9.8

CVE-2024-37831 is a critical SQL injection vulnerability in Itsourcecode Payroll Management System 1.0 that allows attackers to execute arbitrary SQL ...

Jun 14, 2024
CVE-2024-37849
9.8

A SQL injection vulnerability in itsourcecode Billing System 1.0 allows local attackers to execute arbitrary SQL commands via the username parameter i...

Jun 13, 2024
CVE-2024-3552
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Web Directory Free plugin. Attacker...

Jun 13, 2024
CVE-2024-1576
9.8

This SQL injection vulnerability in MegaBIP software allows attackers to execute arbitrary SQL commands, potentially gaining administrator privileges....

Jun 12, 2024
CVE-2024-30163
9.8

This vulnerability allows unauthenticated attackers to perform Blind SQL Injection attacks against Invision Community forums. Attackers can potentiall...

Jun 7, 2024
CVE-2024-36673
9.8

CVE-2024-36673 allows attackers to execute arbitrary SQL commands through the login.php page in Sourcecodester Pharmacy/Medical Store Point of Sale Sy...

Jun 7, 2024
CVE-2024-36779
9.8

CVE-2024-36779 is a critical SQL injection vulnerability in Sourcecodester Stock Management System v1.0 that allows attackers to execute arbitrary SQL...

Jun 6, 2024
CVE-2024-4743
9.8

This SQL injection vulnerability in the LifterLMS WordPress plugin allows authenticated attackers with Contributor-level access or higher to inject ma...

Jun 5, 2024
CVE-2024-4295
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites using the Email Subscribers by Icegram Express...

Jun 5, 2024
CVE-2024-5311
9.8

CVE-2024-5311 is a critical SQL injection vulnerability in DigiWin EasyFlow .NET that allows unauthenticated remote attackers to execute arbitrary SQL...

Jun 3, 2024
CVE-2024-35469
9.8

This SQL injection vulnerability in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the pas...

May 30, 2024
CVE-2024-35349
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the id parameter in the /admin/category/view_category.php file in Diño ...

May 30, 2024
CVE-2024-35354
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the id parameter in Diño Physics School Assistant. It affects all users...

May 30, 2024
CVE-2024-1100
9.8

This SQL injection vulnerability in Vadi Corporate Information Systems DIGIKENT GIS allows attackers to execute arbitrary SQL commands on the database...

May 30, 2024
CVE-2024-35091
9.8

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the findPage function within SysTenantMapper.xml. This allows attackers to execute arbitrary...

May 23, 2024
CVE-2024-34934
9.8

A SQL injection vulnerability in Campcodes Complete Web-Based School Management System 1.0 allows attackers to execute arbitrary SQL commands via the ...

May 23, 2024
CVE-2024-35084
9.8

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the findPage function of SysMsgPushMapper.xml that allows attackers to execute arbitrary SQL...

May 23, 2024
CVE-2024-35086
9.8

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the findPage function of BpmTaskFromMapper.xml. This allows attackers to execute arbitrary S...

May 23, 2024
CVE-2024-34927
9.8

This SQL injection vulnerability in Campcodes Complete Web-Based School Management System 1.0 allows attackers to execute arbitrary SQL commands throu...

May 23, 2024
CVE-2024-34929
9.8

This SQL injection vulnerability in Campcodes Complete Web-Based School Management System 1.0 allows attackers to execute arbitrary SQL commands throu...

May 23, 2024
CVE-2024-34931
9.8

This SQL injection vulnerability in Campcodes Complete Web-Based School Management System 1.0 allows attackers to execute arbitrary SQL commands throu...

May 23, 2024
CVE-2023-51637
9.8

This is a critical SQL injection vulnerability in Sante PACS Server PG that allows unauthenticated remote attackers to execute arbitrary code. Attacke...

May 22, 2024
CVE-2024-35409
9.8

CVE-2024-35409 is a critical SQL injection vulnerability in WeBid 1.1.2 that allows attackers to execute arbitrary SQL commands via the admin/tax.php ...

May 22, 2024
CVE-2024-4443
9.8

This vulnerability allows unauthenticated attackers to perform time-based SQL injection attacks on WordPress sites using the Business Directory Plugin...

May 22, 2024
CVE-2024-35056
9.8

NASA AIT-Core v2.5.2 contains SQL injection vulnerabilities in the query_packets and insert functions that allow attackers to execute arbitrary SQL co...

May 21, 2024
CVE-2024-4826
9.8

This SQL injection vulnerability in Simple PHP Shopping Cart version 0.9 allows attackers to execute arbitrary SQL queries through the category_id par...

May 16, 2024
CVE-2024-4992
9.8

CVE-2024-4992 is a critical SQL injection vulnerability in SiAdmin 1.1 that allows remote attackers to execute arbitrary SQL queries via the nim param...

May 16, 2024
CVE-2024-34955
9.8

Budget Management 1.0 contains a SQL injection vulnerability in the delete parameter that allows attackers to execute arbitrary SQL commands. This aff...

May 15, 2024
CVE-2024-4893
9.8

CVE-2024-4893 is a critical SQL injection vulnerability in DigiWin EasyFlow .NET that allows remote attackers to execute arbitrary SQL commands. This ...

May 15, 2024
CVE-2024-33485
9.8

This SQL injection vulnerability in the CASAP Automated Enrollment System allows remote attackers to execute arbitrary SQL commands via the login.php ...

May 14, 2024
CVE-2024-34256
9.8

OFCMS V1.1.2 contains a SQL injection vulnerability in the new table function that allows attackers to execute arbitrary SQL commands. This affects al...

May 14, 2024
CVE-2024-4824
9.8

CVE-2024-4824 is a critical SQL injection vulnerability in School ERP Pro+Responsive 1.0 that allows remote attackers to execute arbitrary SQL queries...

May 14, 2024
CVE-2024-4434
9.8

This vulnerability allows unauthenticated attackers to perform time-based SQL injection attacks on WordPress sites using the LearnPress plugin. Attack...

May 14, 2024
CVE-2024-25532
9.8

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the bt_id parameter at /include/get_dict.aspx, allowing attackers to execute ...

May 8, 2024
CVE-2024-25530
9.8

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the PageID parameter at /WebUtility/get_find_condiction.aspx. This allows att...

May 8, 2024
CVE-2024-31961
9.8

This SQL injection vulnerability in Sonic Shopfloor.guide's unit.php allows remote attackers to execute arbitrary SQL commands via the level2 paramete...

May 8, 2024
CVE-2024-25523
9.8

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the file_id parameter at /filemanage/file_memo.aspx. This allows attackers to...

May 8, 2024
CVE-2024-25525
9.8

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the filename parameter at /WorkFlow/OfficeFileDownload.aspx. This allows atta...

May 8, 2024
CVE-2024-25517
9.8

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the tbTable parameter at /WebUtility/MF.aspx. This allows attackers to execut...

May 8, 2024
CVE-2024-25519
9.8

RuvarOA versions 6.01 and 12.01 contain a SQL injection vulnerability in the idlist parameter at /WorkFlow/wf_work_print.aspx. This allows attackers t...

May 8, 2024

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,487 CVEs classified as CWE-89, with 1,926 rated critical and 1,910 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free