CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,499
Total CVEs
1,937
Critical
1,911
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
242
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 126
2 Oretnom23 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,499)

CVE-2024-25307
9.8

This vulnerability allows attackers to execute arbitrary SQL commands via the 'id' parameter in the Cinema Seat Reservation System 1.0. This can lead ...

Feb 9, 2024
CVE-2024-25314
9.8

CVE-2024-25314 is a critical SQL injection vulnerability in Code-projects Hotel Management System 1.0 that allows attackers to execute arbitrary SQL c...

Feb 9, 2024
CVE-2024-25316
9.8

This vulnerability allows attackers to execute arbitrary SQL commands via the 'eid' parameter in the Hotel Management System admin panel. It affects C...

Feb 9, 2024
CVE-2023-46350
9.8

This SQL injection vulnerability in the InnovaDeluxe 'Manufacturer or supplier alphabetical search' module for PrestaShop allows remote attackers to e...

Feb 9, 2024
CVE-2024-24308
9.8

This SQL injection vulnerability in the Boostmyshop module for PrestaShop allows remote attackers to execute arbitrary SQL commands. Attackers can esc...

Feb 9, 2024
CVE-2024-24495
9.8

This SQL injection vulnerability in Daily Habit Tracker v1.0 allows remote attackers to execute arbitrary SQL commands via crafted GET requests to del...

Feb 8, 2024
CVE-2023-50061
9.8

This vulnerability allows attackers to execute arbitrary SQL commands on PrestaShop installations using the Op'art Easy Redirect module. Attackers can...

Feb 8, 2024
CVE-2024-1207
9.8

This SQL injection vulnerability in the WP Booking Calendar WordPress plugin allows unauthenticated attackers to inject malicious SQL queries through ...

Feb 8, 2024
CVE-2024-24014
9.8

A SQL injection vulnerability in Novel-Plus v4.3.0-RC1 and earlier allows attackers to execute arbitrary SQL commands by manipulating offset, limit, a...

Feb 8, 2024
CVE-2024-24021
9.8

A SQL injection vulnerability in Novel-Plus v4.3.0-RC1 and earlier allows attackers to execute arbitrary SQL commands by manipulating offset, limit, a...

Feb 8, 2024
CVE-2024-24023
9.8

A SQL injection vulnerability in Novel-Plus v4.3.0-RC1 and earlier allows attackers to inject malicious SQL commands via offset, limit, and sort param...

Feb 8, 2024
CVE-2024-24811
9.8

CVE-2024-24811 is a critical SQL injection vulnerability in SQLAlchemyDA that allows unauthenticated attackers to execute arbitrary SQL statements on ...

Feb 7, 2024
CVE-2024-24133
9.8

CVE-2024-24133 is a critical SQL injection vulnerability in Atmail v6.6.0 that allows attackers to execute arbitrary SQL commands via the username par...

Feb 7, 2024
CVE-2023-46914
9.8

A critical SQL injection vulnerability in the RM bookingcalendar module for PrestaShop allows remote attackers to execute arbitrary SQL commands via t...

Feb 7, 2024
CVE-2024-24019
9.8

A SQL injection vulnerability in Novel-Plus v4.3.0-RC1 and earlier allows attackers to execute arbitrary SQL commands via crafted offset, limit, and s...

Feb 7, 2024
CVE-2024-24004
9.8

CVE-2024-24004 is a critical SQL injection vulnerability in jshERP v3.3 that allows attackers to bypass the application's SQL protection mechanism. At...

Feb 7, 2024
CVE-2024-24001
9.8

jshERP v3.3 contains a SQL injection vulnerability in the findallocationDetail() function that allows attackers to bypass the application's protection...

Feb 7, 2024
CVE-2024-24015
9.8

A SQL injection vulnerability in Novel-Plus v4.3.0-RC1 and earlier allows attackers to execute arbitrary SQL commands via crafted offset, limit, and s...

Feb 6, 2024
CVE-2024-24112
9.8

CVE-2024-24112 is a SQL injection vulnerability in xmall v1.1 that allows attackers to execute arbitrary SQL commands via the orderDir parameter. This...

Feb 6, 2024
CVE-2023-51951
9.8

This SQL injection vulnerability in Stock Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in mana...

Feb 5, 2024
CVE-2024-22108
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection against GTB Central Console, enabling them to change the administrator pa...

Feb 2, 2024
CVE-2024-24029
9.8

JFinalCMS 5.0.0 contains a SQL injection vulnerability in the /admin/content/data endpoint that allows attackers to execute arbitrary SQL commands. Th...

Feb 2, 2024
CVE-2023-48792
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the report export feature in Zoho ManageEngine ADAudit Plus. Organizatio...

Feb 2, 2024
CVE-2022-47072
9.8

This SQL injection vulnerability in Enterprise Architect allows attackers to execute arbitrary SQL commands through the Find parameter in the Select C...

Jan 31, 2024
CVE-2024-24141
9.8

CVE-2024-24141 is a critical SQL injection vulnerability in the School Task Manager App 1.0 that allows attackers to execute arbitrary SQL commands vi...

Jan 29, 2024
CVE-2023-48118
9.8

This SQL injection vulnerability in Quest Analytics IQCRM allows remote attackers to execute arbitrary SQL commands via crafted requests to the Common...

Jan 22, 2024
CVE-2024-23751
9.8

This CVE describes a SQL injection vulnerability in LlamaIndex's Text-to-SQL feature that allows attackers to execute arbitrary SQL commands through n...

Jan 22, 2024
CVE-2023-51927
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the YonBIP HR attendance script controller. It affects organizations usi...

Jan 20, 2024
CVE-2023-46351
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries on PrestaShop installations using the mib module from MyPresta.eu...

Jan 19, 2024
CVE-2023-50030
9.8

This vulnerability allows unauthenticated attackers to perform blind SQL injection attacks on PrestaShop installations using the vulnerable Jms Settin...

Jan 19, 2024
CVE-2024-0705
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites using the Stripe Payment Plugin for WooCommerc...

Jan 19, 2024
CVE-2023-5806
9.8

This SQL injection vulnerability in Mergen Software Quality Management System allows attackers to execute arbitrary SQL commands through unvalidated u...

Jan 18, 2024
CVE-2023-3211
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Database Administrator plugin. Atta...

Jan 16, 2024
CVE-2023-0224
9.8

CVE-2023-0224 is an SQL injection vulnerability in the GiveWP WordPress plugin that allows unauthenticated attackers to execute arbitrary SQL commands...

Jan 16, 2024
CVE-2023-30016
9.8

A critical SQL injection vulnerability in oretnom23 Judging Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the s...

Jan 12, 2024
CVE-2023-30014
9.8

This CVE describes a critical SQL injection vulnerability in oretnom23 Judging Management System v1.0. Attackers can exploit the sub_event_id paramete...

Jan 12, 2024
CVE-2023-6567
9.8

This vulnerability allows unauthenticated attackers to perform time-based SQL injection attacks on WordPress sites using the LearnPress plugin. Attack...

Jan 11, 2024
CVE-2023-52064
9.8

Wuzhicms v4.1.0 contains a SQL injection vulnerability in the $keywords parameter at /core/admin/copyfrom.php. This allows attackers to execute arbitr...

Jan 10, 2024
CVE-2023-6921
9.8

CVE-2023-6921 is a blind SQL injection vulnerability in the PrestaShow Google Integrator addon for PrestaShop that allows attackers to extract or modi...

Jan 8, 2024
CVE-2023-46953
9.8

A SQL injection vulnerability in ABO.CMS v5.9.3 allows remote attackers to execute arbitrary SQL commands via the 'd' parameter in the Documents modul...

Jan 6, 2024
CVE-2023-50864
9.8

Travel Website v1.0 contains unauthenticated SQL injection vulnerabilities in the hotelDetails.php resource, allowing attackers to execute arbitrary S...

Jan 4, 2024
CVE-2023-50866
9.8

Travel Website v1.0 has unauthenticated SQL injection vulnerabilities in the loginAction.php file, specifically in the username parameter. Attackers c...

Jan 4, 2024
CVE-2023-50862
9.8

Travel Website v1.0 contains an unauthenticated SQL injection vulnerability in the booking.php resource's hotelIDHidden parameter. Attackers can execu...

Jan 4, 2024
CVE-2023-50743
9.8

Online Notice Board System v1.0 contains unauthenticated SQL injection vulnerabilities in the registration.php resource. Attackers can execute arbitra...

Jan 4, 2024
CVE-2023-50753
9.8

Online Notice Board System v1.0 contains unauthenticated SQL injection vulnerabilities in the user/update_profile.php endpoint. Attackers can execute ...

Jan 4, 2024
CVE-2023-49625
9.8

Billing Software v1.0 contains unauthenticated SQL injection vulnerabilities in the partylist_edit_submit.php resource, allowing attackers to execute ...

Jan 4, 2024
CVE-2023-49639
9.8

Billing Software v1.0 contains unauthenticated SQL injection vulnerabilities in the buyer_invoice_submit.php file, specifically in the 'customer_detai...

Jan 4, 2024
CVE-2023-49665
9.8

Billing Software v1.0 contains unauthenticated SQL injection vulnerabilities in the submit_delivery_list.php resource. Attackers can exploit the 'quan...

Jan 4, 2024
CVE-2023-49622
9.8

Billing Software v1.0 contains unauthenticated SQL injection vulnerabilities in the 'itemnameid' parameter of material_bill.php?action=itemRelation. T...

Jan 4, 2024
CVE-2023-6436
9.8

This SQL injection vulnerability in Ekol Informatics Website Template allows attackers to execute arbitrary SQL commands through user inputs. All webs...

Jan 2, 2024

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,499 CVEs classified as CWE-89, with 1,937 rated critical and 1,911 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free