CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,487
Total CVEs
1,926
Critical
1,910
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
241
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 126
2 Oretnom23 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,487)

CVE-2024-33164
9.8

CVE-2024-33164 is a critical SQL injection vulnerability in J2EEFAST v2.7.0 that allows attackers to execute arbitrary SQL commands via the sql_filter...

May 7, 2024
CVE-2024-33153
9.8

J2EEFAST v2.7.0 contains a SQL injection vulnerability in the commentList() function via the sql_filter parameter. This allows attackers to execute ar...

May 7, 2024
CVE-2024-33124
9.8

CVE-2024-33124 is a critical SQL injection vulnerability in Roothub v2.6 that allows attackers to execute arbitrary SQL commands via the nodeTitle par...

May 7, 2024
CVE-2024-34532
9.8

A SQL injection vulnerability in the Yvan Dotet PostgreSQL Query Deluxe module allows remote attackers to execute arbitrary SQL commands via the query...

May 6, 2024
CVE-2024-33408
9.8

A SQL injection vulnerability in campcodes Complete Web-Based School Management System 1.0 allows attackers to execute arbitrary SQL commands via the ...

May 6, 2024
CVE-2024-33411
9.8

A SQL injection vulnerability in Campcodes Complete Web-Based School Management System 1.0 allows attackers to execute arbitrary SQL commands via the ...

May 6, 2024
CVE-2024-33403
9.8

A SQL injection vulnerability in campcodes Complete Web-Based School Management System 1.0 allows attackers to execute arbitrary SQL commands via the ...

May 6, 2024
CVE-2024-31673
9.8

Kliqqi-CMS 2.0.2 contains a SQL injection vulnerability in load_data.php through the userid parameter. This allows attackers to execute arbitrary SQL ...

May 3, 2024
CVE-2024-4466
9.8

This SQL injection vulnerability in Gescen on centrosdigitales.net allows attackers to execute arbitrary SQL queries through the pass parameter, poten...

May 3, 2024
CVE-2023-51595
9.8

This is an unauthenticated SQL injection vulnerability in Voltronic Power ViewPower Pro that allows remote attackers to execute arbitrary code. Attack...

May 3, 2024
CVE-2023-51586
9.8

This is a critical SQL injection vulnerability in Voltronic Power ViewPower Pro that allows unauthenticated remote attackers to execute arbitrary code...

May 3, 2024
CVE-2024-33273
9.8

This SQL injection vulnerability in shipup versions before 3.3.0 allows remote attackers to execute arbitrary SQL commands via the getShopID function....

Apr 30, 2024
CVE-2024-33275
9.8

This SQL injection vulnerability in Webbax supernewsletter v1.4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the produ...

Apr 30, 2024
CVE-2024-33267
9.8

This CVE describes a critical SQL injection vulnerability in the Hero hfheropayment PrestaShop module that allows attackers to execute arbitrary SQL c...

Apr 30, 2024
CVE-2024-33266
9.8

This CVE describes a critical SQL injection vulnerability in the Helloshop deliveryorderautoupdate PrestaShop module. Attackers can execute arbitrary ...

Apr 29, 2024
CVE-2024-33269
9.8

This CVE describes a critical SQL injection vulnerability in the Prestaddons flashsales module for PrestaShop. Attackers can execute arbitrary SQL com...

Apr 29, 2024
CVE-2024-33276
9.8

This CVE describes a SQL injection vulnerability in the FME Modules preorderandnotification module for PrestaShop. Attackers can execute arbitrary SQL...

Apr 29, 2024
CVE-2024-33444
9.8

CVE-2024-33444 is a critical SQL injection vulnerability in onethink v1.1 that allows remote attackers to execute arbitrary SQL commands via the Model...

Apr 29, 2024
CVE-2024-28322
9.8

This is a critical SQL injection vulnerability in PuneethReddyHC Event Management 1.0 that allows attackers to execute arbitrary SQL commands via the ...

Apr 26, 2024
CVE-2024-28613
9.8

This SQL injection vulnerability in PHP Task Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the task_id paramete...

Apr 24, 2024
CVE-2024-30938
9.8

This SQL injection vulnerability in SEMCMS v4.8 allows remote attackers to extract sensitive database information by manipulating the ID parameter in ...

Apr 19, 2024
CVE-2024-30922
9.8

A critical SQL injection vulnerability in DerbyNet v9.0 allows remote attackers to execute arbitrary SQL commands via the where clause in award docume...

Apr 18, 2024
CVE-2024-30990
9.8

This CVE describes a critical SQL injection vulnerability in the Invoices page of phpgurukul Client Management System. Attackers can execute arbitrary...

Apr 17, 2024
CVE-2024-30982
9.8

This CVE describes a critical SQL injection vulnerability in phpgurukul Cyber Cafe Management System 1.0. Attackers can execute arbitrary SQL commands...

Apr 17, 2024
CVE-2024-30980
9.8

This SQL injection vulnerability in phpgurukul Cyber Cafe Management System allows attackers to execute arbitrary SQL commands via the Computer Locati...

Apr 17, 2024
CVE-2024-1601
9.8

An SQL injection vulnerability in the parisneo/lollms-webui application allows attackers to delete all discussion and message data by sending a crafte...

Apr 16, 2024
CVE-2024-28556
9.8

This CVE describes a critical SQL injection vulnerability in the Sourcecodester PHP Task Management System v1.0. Attackers can exploit this via crafte...

Apr 15, 2024
CVE-2024-3704
9.8

CVE-2024-3704 is a critical SQL injection vulnerability in OpenGnsys version 1.1.1d that allows attackers to bypass authentication and potentially acc...

Apr 12, 2024
CVE-2024-31678
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the password parameter in the login.php file of Sourcecodester Loan Mana...

Apr 11, 2024
CVE-2024-30998
9.8

This CVE describes a critical SQL injection vulnerability in PHPGurukul Men Salon Management System v2.0, allowing remote attackers to execute arbitra...

Apr 3, 2024
CVE-2024-2879
9.8

The LayerSlider WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries. This ...

Apr 3, 2024
CVE-2024-29432
9.8

Alldata v0.4.6 contains a SQL injection vulnerability in the tablename parameter at the /data/masterdata/datas endpoint. This allows attackers to exec...

Apr 2, 2024
CVE-2024-1863
9.8

This is a critical SQL injection vulnerability in Sante PACS Server's token endpoint that allows unauthenticated remote attackers to execute arbitrary...

Apr 1, 2024
CVE-2024-30867
9.8

This SQL injection vulnerability in netentsec NS-ASG 6.3 allows attackers to execute arbitrary SQL commands via the /admin/edit_virtual_site_info.php ...

Apr 1, 2024
CVE-2024-30865
9.8

CVE-2024-30865 is a critical SQL injection vulnerability in netentsec NS-ASG 6.3 that allows attackers to execute arbitrary SQL commands via the /admi...

Apr 1, 2024
CVE-2023-6191
9.8

This SQL injection vulnerability in Egehan Security WebPDKS allows attackers to execute arbitrary SQL commands on the database. All installations of W...

Mar 29, 2024
CVE-2023-6173
9.8

This SQL injection vulnerability in TeoSOFT Software TeoBASE allows attackers to execute arbitrary SQL commands through unvalidated user input. All Te...

Mar 27, 2024
CVE-2024-29303
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the delete admin users function in SourceCodester PHP Task Management Sy...

Mar 26, 2024
CVE-2024-28421
9.8

CVE-2024-28421 is a critical SQL injection vulnerability in Razor 0.8.0 that allows remote attackers to execute arbitrary SQL commands via the Channel...

Mar 25, 2024
CVE-2024-28393
9.8

This SQL injection vulnerability in the scalapay PrestaShop module allows remote attackers to execute arbitrary SQL commands via the ScalapayReturnMod...

Mar 25, 2024
CVE-2024-2865
9.8

This SQL injection vulnerability in Mergen Software Quality Management System allows attackers to execute arbitrary SQL commands through unvalidated u...

Mar 25, 2024
CVE-2024-2722
9.8

This SQL injection vulnerability in the CIGESv2 system allows remote attackers to execute arbitrary SQL commands through the 'id' parameter in /ajaxCo...

Mar 22, 2024
CVE-2024-2724
9.8

This SQL injection vulnerability in the CIGESv2 system allows remote attackers to execute arbitrary SQL queries through the 'idServicio' parameter in ...

Mar 22, 2024
CVE-2024-29275
9.8

This critical SQL injection vulnerability in SeaCMS version 12.9 allows unauthenticated attackers to execute arbitrary SQL commands via the id paramet...

Mar 22, 2024
CVE-2024-29871
9.8

This SQL injection vulnerability in Sentrifugo 3.2 allows remote attackers to execute arbitrary SQL commands through the 'id' parameter in specific en...

Mar 21, 2024
CVE-2024-29873
9.8

This SQL injection vulnerability in Sentrifugo 3.2 allows remote attackers to execute arbitrary SQL queries through the 'bunitname' parameter in the b...

Mar 21, 2024
CVE-2024-29875
9.8

This is a critical SQL injection vulnerability in Sentrifugo 3.2 that allows remote attackers to execute arbitrary SQL queries through the 'sort_name'...

Mar 21, 2024
CVE-2024-29732
9.8

An unauthenticated SQL injection vulnerability exists in the SCAN_VISIO eDocument Suite Web Viewer login page via the 'user' parameter. This allows at...

Mar 21, 2024
CVE-2023-48901
9.8

This SQL injection vulnerability in tramyardg Autoexpress 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the 'id'...

Mar 21, 2024
CVE-2024-25239
9.8

This CVE describes a critical SQL injection vulnerability in Sourcecodester Employee Management System v1.0, allowing attackers to execute arbitrary S...

Mar 21, 2024

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,487 CVEs classified as CWE-89, with 1,926 rated critical and 1,910 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free