CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,493
Total CVEs
1,932
Critical
1,910
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
242
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 126
2 Oretnom23 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,493)

CVE-2023-48901
9.8

This SQL injection vulnerability in tramyardg Autoexpress 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the 'id'...

Mar 21, 2024
CVE-2024-25239
9.8

This CVE describes a critical SQL injection vulnerability in Sourcecodester Employee Management System v1.0, allowing attackers to execute arbitrary S...

Mar 21, 2024
CVE-2024-28392
9.8

This SQL injection vulnerability in the pscartabandonmentpro PrestaShop module allows remote attackers to execute arbitrary SQL commands via the setEm...

Mar 20, 2024
CVE-2024-28389
9.8

This SQL injection vulnerability in KnowBand spinwheel v3.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the sendEmail(...

Mar 19, 2024
CVE-2024-28303
9.8

CVE-2024-28303 is a critical SQL injection vulnerability in Open Source Medicine Ordering System v1.0 that allows attackers to execute arbitrary SQL c...

Mar 19, 2024
CVE-2024-25227
9.8

CVE-2024-25227 is a critical SQL injection vulnerability in ABO.CMS version 5.8 that allows remote attackers to execute arbitrary SQL commands via the...

Mar 15, 2024
CVE-2024-28388
9.8

This SQL injection vulnerability in the SunnyToo stproductcomments module for PrestaShop allows remote attackers to execute arbitrary SQL commands. At...

Mar 14, 2024
CVE-2024-25250
9.8

This SQL injection vulnerability in Agro-School Management System 1.0 allows attackers to execute arbitrary SQL commands through the login page. Attac...

Mar 13, 2024
CVE-2024-1071
9.8

This SQL injection vulnerability in the Ultimate Member WordPress plugin allows unauthenticated attackers to inject malicious SQL queries through the ...

Mar 13, 2024
CVE-2024-24101
9.8

Scholars Tracking System 1.0 contains a SQL injection vulnerability in the Eligibility Information Update functionality that allows attackers to execu...

Mar 12, 2024
CVE-2024-24093
9.8

This SQL injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to execute arbitrary SQL commands through the Personal...

Mar 12, 2024
CVE-2024-1301
9.8

This SQL injection vulnerability in Badger Meter Monitool allows remote attackers to execute arbitrary SQL queries via the j_username parameter. Attac...

Mar 12, 2024
CVE-2024-25845
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks against PrestaShop installations using the 'CD Custom Fields 4 Or...

Mar 8, 2024
CVE-2024-25849
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on PrestaShop websites using the 'Make an offer' module version 1...

Mar 8, 2024
CVE-2023-41014
9.8

CVE-2023-41014 is a critical SQL injection vulnerability in code-projects.org Online Job Portal 1.0 that allows attackers to execute arbitrary SQL com...

Mar 7, 2024
CVE-2023-49989
9.8

Hotel Booking Management v1.0 contains a SQL injection vulnerability in the id parameter of update.php, allowing attackers to execute arbitrary SQL co...

Mar 7, 2024
CVE-2024-27304
9.8

This CVE describes an SQL injection vulnerability in the pgx PostgreSQL driver for Go. An integer overflow when processing extremely large queries (ov...

Mar 6, 2024
CVE-2023-49547
9.8

CVE-2023-49547 is a critical SQL injection vulnerability in Customer Support System v1 that allows attackers to execute arbitrary SQL commands via the...

Mar 5, 2024
CVE-2023-49970
9.8

This SQL injection vulnerability in Customer Support System v1 allows attackers to execute arbitrary SQL commands via the subject parameter in the sav...

Mar 5, 2024
CVE-2024-27746
9.8

This CVE describes a SQL injection vulnerability in Petrol Pump Management Software v1.0 that allows attackers to execute arbitrary SQL commands via t...

Mar 1, 2024
CVE-2024-1981
9.8

CVE-2024-1981 is a critical SQL injection vulnerability in the WPvivid Backup and Migration WordPress plugin that allows unauthenticated attackers to ...

Feb 29, 2024
CVE-2024-25833
9.8

F-logic DataCube3 v1.0 has an unauthenticated SQL injection vulnerability that allows attackers to execute arbitrary SQL queries without authenticatio...

Feb 29, 2024
CVE-2024-25422
9.8

This SQL injection vulnerability in SEMCMS v4.8 allows remote attackers to execute arbitrary SQL commands through the SEMCMS_Menu.php component. Attac...

Feb 28, 2024
CVE-2024-25910
9.8

This CVE describes an unauthenticated SQL injection vulnerability in the Skymoonlabs MoveTo WordPress plugin. Attackers can execute arbitrary SQL comm...

Feb 28, 2024
CVE-2024-1514
9.8

The WP eCommerce plugin for WordPress has a critical SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL querie...

Feb 28, 2024
CVE-2024-25843
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on PrestaShop installations using the affected ba_importer modul...

Feb 27, 2024
CVE-2024-25400
9.8

This disputed CVE claims Subrion CMS 4.2.1 has SQL injection vulnerability in ia.core.mysqli.php, potentially allowing attackers to execute arbitrary ...

Feb 27, 2024
CVE-2024-1698
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites using the NotificationX plugin. Attackers can ...

Feb 27, 2024
CVE-2024-24095
9.8

Simple Stock System 1.0 contains a SQL injection vulnerability that allows attackers to execute arbitrary SQL commands on the database. This affects a...

Feb 27, 2024
CVE-2024-25247
9.8

This SQL injection vulnerability in Niushop B2B2C V5 allows attackers to execute arbitrary SQL commands through latitude and longitude parameters in t...

Feb 26, 2024
CVE-2024-25248
9.8

This SQL injection vulnerability in Niushop B2B2C V5 allows attackers to execute arbitrary SQL commands through the order_id parameter in the orderGoo...

Feb 26, 2024
CVE-2024-24401
9.8

A critical SQL injection vulnerability in Nagios XI 2024R1.01 allows remote attackers to execute arbitrary SQL commands via the monitoringwizard.php c...

Feb 26, 2024
CVE-2023-37177
9.8

This CVE describes a critical SQL injection vulnerability in PMB Services library management software that allows unauthenticated remote attackers to ...

Feb 21, 2024
CVE-2024-25897
9.8

ChurchCRM 5.5.0 contains a blind SQL injection vulnerability in FRCatalog.php via the CurrentFundraiser GET parameter. Attackers can exploit this to e...

Feb 21, 2024
CVE-2024-0610
9.8

The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL injection via the 'MerchantReference' paramete...

Feb 17, 2024
CVE-2024-25320
9.8

This CVE describes a SQL injection vulnerability in Tongda OA software that allows attackers to execute arbitrary SQL commands via the $AFF_ID paramet...

Feb 16, 2024
CVE-2023-7081
9.8

This SQL injection vulnerability in POSTAHSİL Online Payment System allows attackers to execute arbitrary SQL commands through user inputs. It affect...

Feb 15, 2024
CVE-2023-5155
9.8

This SQL injection vulnerability in Utarit Information Technologies SoliPay Mobile App allows attackers to execute arbitrary SQL commands against the ...

Feb 15, 2024
CVE-2024-26264
9.8

CVE-2024-26264 is an unauthenticated SQL injection vulnerability in EBM Technologies RISWEB's query function. Remote attackers can execute arbitrary S...

Feb 15, 2024
CVE-2024-25211
9.8

Simple Expense Tracker v1.0 contains a SQL injection vulnerability in the category parameter at /endpoint/delete_category.php. This allows attackers t...

Feb 14, 2024
CVE-2024-25214
9.8

CVE-2024-25214 is an authentication bypass vulnerability in Employee Management System v1.0 that allows attackers to gain unauthorized access by injec...

Feb 14, 2024
CVE-2024-25216
9.8

Employee Management System v1.0 contains a SQL injection vulnerability in the mailud parameter at /aprocess.php. This allows attackers to execute arbi...

Feb 14, 2024
CVE-2024-25220
9.8

Task Manager App v1.0 contains a SQL injection vulnerability in the EditTask.php endpoint via the taskID parameter. This allows attackers to execute a...

Feb 14, 2024
CVE-2024-25222
9.8

Task Manager App v1.0 contains a SQL injection vulnerability in the projectID parameter at /TaskManager/EditProject.php. This allows attackers to exec...

Feb 14, 2024
CVE-2024-25209
9.8

Barangay Population Monitoring System 1.0 contains a SQL injection vulnerability in the delete-resident.php endpoint that allows attackers to execute ...

Feb 14, 2024
CVE-2023-6441
9.8

This SQL injection vulnerability in UNI-PA University Information System allows attackers to execute arbitrary SQL commands through user inputs. It af...

Feb 14, 2024
CVE-2024-24142
9.8

CVE-2024-24142 is a critical SQL injection vulnerability in School Task Manager 1.0 that allows attackers to execute arbitrary SQL commands via the 's...

Feb 13, 2024
CVE-2024-22923
9.8

This SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary SQL commands via a crafted script. Attackers could...

Feb 13, 2024
CVE-2024-23763
9.8

This SQL injection vulnerability in Gambio e-commerce software allows attackers to execute arbitrary SQL commands through crafted GET requests targeti...

Feb 12, 2024
CVE-2023-6677
9.8

This SQL injection vulnerability in Oduyo Financial Technology Online Collection allows attackers to execute arbitrary SQL commands by injecting malic...

Feb 9, 2024

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,493 CVEs classified as CWE-89, with 1,932 rated critical and 1,910 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free