CWE-89: SQL Injection
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Yearly Trend
Top Affected Vendors
All SQL Injection CVEs (4,487)
CVE-2024-33164 is a critical SQL injection vulnerability in J2EEFAST v2.7.0 that allows attackers to execute arbitrary SQL commands via the sql_filter...
May 7, 2024J2EEFAST v2.7.0 contains a SQL injection vulnerability in the commentList() function via the sql_filter parameter. This allows attackers to execute ar...
May 7, 2024CVE-2024-33124 is a critical SQL injection vulnerability in Roothub v2.6 that allows attackers to execute arbitrary SQL commands via the nodeTitle par...
May 7, 2024A SQL injection vulnerability in the Yvan Dotet PostgreSQL Query Deluxe module allows remote attackers to execute arbitrary SQL commands via the query...
May 6, 2024A SQL injection vulnerability in campcodes Complete Web-Based School Management System 1.0 allows attackers to execute arbitrary SQL commands via the ...
May 6, 2024A SQL injection vulnerability in Campcodes Complete Web-Based School Management System 1.0 allows attackers to execute arbitrary SQL commands via the ...
May 6, 2024A SQL injection vulnerability in campcodes Complete Web-Based School Management System 1.0 allows attackers to execute arbitrary SQL commands via the ...
May 6, 2024Kliqqi-CMS 2.0.2 contains a SQL injection vulnerability in load_data.php through the userid parameter. This allows attackers to execute arbitrary SQL ...
May 3, 2024This SQL injection vulnerability in Gescen on centrosdigitales.net allows attackers to execute arbitrary SQL queries through the pass parameter, poten...
May 3, 2024This is an unauthenticated SQL injection vulnerability in Voltronic Power ViewPower Pro that allows remote attackers to execute arbitrary code. Attack...
May 3, 2024This is a critical SQL injection vulnerability in Voltronic Power ViewPower Pro that allows unauthenticated remote attackers to execute arbitrary code...
May 3, 2024This SQL injection vulnerability in shipup versions before 3.3.0 allows remote attackers to execute arbitrary SQL commands via the getShopID function....
Apr 30, 2024This SQL injection vulnerability in Webbax supernewsletter v1.4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the produ...
Apr 30, 2024This CVE describes a critical SQL injection vulnerability in the Hero hfheropayment PrestaShop module that allows attackers to execute arbitrary SQL c...
Apr 30, 2024This CVE describes a critical SQL injection vulnerability in the Helloshop deliveryorderautoupdate PrestaShop module. Attackers can execute arbitrary ...
Apr 29, 2024This CVE describes a critical SQL injection vulnerability in the Prestaddons flashsales module for PrestaShop. Attackers can execute arbitrary SQL com...
Apr 29, 2024This CVE describes a SQL injection vulnerability in the FME Modules preorderandnotification module for PrestaShop. Attackers can execute arbitrary SQL...
Apr 29, 2024CVE-2024-33444 is a critical SQL injection vulnerability in onethink v1.1 that allows remote attackers to execute arbitrary SQL commands via the Model...
Apr 29, 2024This is a critical SQL injection vulnerability in PuneethReddyHC Event Management 1.0 that allows attackers to execute arbitrary SQL commands via the ...
Apr 26, 2024This SQL injection vulnerability in PHP Task Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the task_id paramete...
Apr 24, 2024This SQL injection vulnerability in SEMCMS v4.8 allows remote attackers to extract sensitive database information by manipulating the ID parameter in ...
Apr 19, 2024A critical SQL injection vulnerability in DerbyNet v9.0 allows remote attackers to execute arbitrary SQL commands via the where clause in award docume...
Apr 18, 2024This CVE describes a critical SQL injection vulnerability in the Invoices page of phpgurukul Client Management System. Attackers can execute arbitrary...
Apr 17, 2024This CVE describes a critical SQL injection vulnerability in phpgurukul Cyber Cafe Management System 1.0. Attackers can execute arbitrary SQL commands...
Apr 17, 2024This SQL injection vulnerability in phpgurukul Cyber Cafe Management System allows attackers to execute arbitrary SQL commands via the Computer Locati...
Apr 17, 2024An SQL injection vulnerability in the parisneo/lollms-webui application allows attackers to delete all discussion and message data by sending a crafte...
Apr 16, 2024This CVE describes a critical SQL injection vulnerability in the Sourcecodester PHP Task Management System v1.0. Attackers can exploit this via crafte...
Apr 15, 2024CVE-2024-3704 is a critical SQL injection vulnerability in OpenGnsys version 1.1.1d that allows attackers to bypass authentication and potentially acc...
Apr 12, 2024This vulnerability allows attackers to execute arbitrary SQL commands through the password parameter in the login.php file of Sourcecodester Loan Mana...
Apr 11, 2024This CVE describes a critical SQL injection vulnerability in PHPGurukul Men Salon Management System v2.0, allowing remote attackers to execute arbitra...
Apr 3, 2024The LayerSlider WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries. This ...
Apr 3, 2024Alldata v0.4.6 contains a SQL injection vulnerability in the tablename parameter at the /data/masterdata/datas endpoint. This allows attackers to exec...
Apr 2, 2024This is a critical SQL injection vulnerability in Sante PACS Server's token endpoint that allows unauthenticated remote attackers to execute arbitrary...
Apr 1, 2024This SQL injection vulnerability in netentsec NS-ASG 6.3 allows attackers to execute arbitrary SQL commands via the /admin/edit_virtual_site_info.php ...
Apr 1, 2024CVE-2024-30865 is a critical SQL injection vulnerability in netentsec NS-ASG 6.3 that allows attackers to execute arbitrary SQL commands via the /admi...
Apr 1, 2024This SQL injection vulnerability in Egehan Security WebPDKS allows attackers to execute arbitrary SQL commands on the database. All installations of W...
Mar 29, 2024This SQL injection vulnerability in TeoSOFT Software TeoBASE allows attackers to execute arbitrary SQL commands through unvalidated user input. All Te...
Mar 27, 2024This vulnerability allows attackers to execute arbitrary SQL commands through the delete admin users function in SourceCodester PHP Task Management Sy...
Mar 26, 2024CVE-2024-28421 is a critical SQL injection vulnerability in Razor 0.8.0 that allows remote attackers to execute arbitrary SQL commands via the Channel...
Mar 25, 2024This SQL injection vulnerability in the scalapay PrestaShop module allows remote attackers to execute arbitrary SQL commands via the ScalapayReturnMod...
Mar 25, 2024This SQL injection vulnerability in Mergen Software Quality Management System allows attackers to execute arbitrary SQL commands through unvalidated u...
Mar 25, 2024This SQL injection vulnerability in the CIGESv2 system allows remote attackers to execute arbitrary SQL commands through the 'id' parameter in /ajaxCo...
Mar 22, 2024This SQL injection vulnerability in the CIGESv2 system allows remote attackers to execute arbitrary SQL queries through the 'idServicio' parameter in ...
Mar 22, 2024This critical SQL injection vulnerability in SeaCMS version 12.9 allows unauthenticated attackers to execute arbitrary SQL commands via the id paramet...
Mar 22, 2024This SQL injection vulnerability in Sentrifugo 3.2 allows remote attackers to execute arbitrary SQL commands through the 'id' parameter in specific en...
Mar 21, 2024This SQL injection vulnerability in Sentrifugo 3.2 allows remote attackers to execute arbitrary SQL queries through the 'bunitname' parameter in the b...
Mar 21, 2024This is a critical SQL injection vulnerability in Sentrifugo 3.2 that allows remote attackers to execute arbitrary SQL queries through the 'sort_name'...
Mar 21, 2024An unauthenticated SQL injection vulnerability exists in the SCAN_VISIO eDocument Suite Web Viewer login page via the 'user' parameter. This allows at...
Mar 21, 2024This SQL injection vulnerability in tramyardg Autoexpress 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the 'id'...
Mar 21, 2024This CVE describes a critical SQL injection vulnerability in Sourcecodester Employee Management System v1.0, allowing attackers to execute arbitrary S...
Mar 21, 2024About SQL Injection (CWE-89)
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Our database tracks 4,487 CVEs classified as CWE-89, with 1,926 rated critical and 1,910 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.
External reference: View CWE-89 on MITRE CWE →
Monitor SQL Injection Vulnerabilities
Get alerted when new SQL Injection CVEs affect your infrastructure.
Start Monitoring Free