CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,506
Total CVEs
1,938
Critical
1,917
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
242
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 126
2 Oretnom23 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 46
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Ivanti 35

All SQL Injection CVEs (4,506)

CVE-2023-50589
9.8

This SQL injection vulnerability in Grupo Embras GEOSIAP ERP allows attackers to execute arbitrary SQL commands via the codLogin parameter on the logi...

Dec 30, 2023
CVE-2023-50578
9.8

Mingsoft MCMS v5.2.9 contains a SQL injection vulnerability in the categoryType parameter at /content/list.do. This allows attackers to execute arbitr...

Dec 30, 2023
CVE-2023-41542
9.8

This SQL injection vulnerability in jeecg-boot version 3.5.3 allows remote attackers to execute arbitrary SQL commands via the jmreport/qurestSql comp...

Dec 30, 2023
CVE-2023-50035
9.8

PHPGurukul Small CRM 3.0 has a critical SQL injection vulnerability in the login panel's password parameter that allows attackers to execute arbitrary...

Dec 29, 2023
CVE-2023-4541
9.8

This SQL injection vulnerability in Ween Software Admin Panel allows attackers to execute arbitrary SQL commands through the admin interface. It affec...

Dec 29, 2023
CVE-2023-4675
9.8

This SQL injection vulnerability in GM Information Technologies MDO allows attackers to execute arbitrary SQL commands on the database. It affects all...

Dec 29, 2023
CVE-2023-23634
9.8

This SQL injection vulnerability in Documize version 5.4.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in the /ap...

Dec 29, 2023
CVE-2023-4671
9.8

This SQL injection vulnerability in Talent Software ECOP allows attackers to execute arbitrary SQL commands, potentially leading to command line execu...

Dec 28, 2023
CVE-2023-49954
9.8

This SQL injection vulnerability in 3CX CRM Integration allows attackers to execute arbitrary SQL commands by manipulating first name, search string, ...

Dec 25, 2023
CVE-2022-47532
9.8

CVE-2022-47532 is a SQL injection vulnerability in FileRun 20220519 that allows attackers to execute arbitrary SQL commands via the 'dir' parameter in...

Dec 22, 2023
CVE-2023-49688
9.8

Job Portal v1.0 contains unauthenticated SQL injection vulnerabilities in the login.php file, specifically in the 'txtUser' parameter. Attackers can e...

Dec 22, 2023
CVE-2023-49681
9.8

Job Portal v1.0 contains an unauthenticated SQL injection vulnerability in the 'cmbQual' parameter of Employer/InsertWalkin.php. Attackers can execute...

Dec 21, 2023
CVE-2023-49677
9.8

Job Portal v1.0 contains an unauthenticated SQL injection vulnerability in the 'cmbQual' parameter of Employer/InsertJob.php. Attackers can execute ar...

Dec 21, 2023
CVE-2023-48718
9.8

Student Result Management System v1.0 contains unauthenticated SQL injection vulnerabilities in the 'class_name' parameter of add_students.php. Attack...

Dec 21, 2023
CVE-2023-48720
9.8

CVE-2023-48720 is an unauthenticated SQL injection vulnerability in Student Result Management System v1.0's login.php page. Attackers can execute arbi...

Dec 21, 2023
CVE-2023-48689
9.8

Railway Reservation System v1.0 contains unauthenticated SQL injection vulnerabilities in the train.php resource's 'byname' parameter. Attackers can e...

Dec 21, 2023
CVE-2023-48716
9.8

CVE-2023-48716 allows unauthenticated attackers to execute arbitrary SQL commands through the 'class_id' parameter in add_classes.php. This affects St...

Dec 21, 2023
CVE-2023-48687
9.8

Railway Reservation System v1.0 contains unauthenticated SQL injection vulnerabilities in the 'from' parameter of reservation.php. Attackers can execu...

Dec 21, 2023
CVE-2023-48685
9.8

CVE-2023-48685 allows unauthenticated attackers to execute arbitrary SQL commands through the 'psd' parameter in Railway Reservation System v1.0's log...

Dec 21, 2023
CVE-2023-51050
9.8

S-CMS v5.0 contains a SQL injection vulnerability in the A_productauth parameter at /admin/ajax.php. This allows attackers to execute arbitrary SQL co...

Dec 21, 2023
CVE-2023-51052
9.8

S-CMS v5.0 contains a SQL injection vulnerability in the A_formauth parameter at /admin/ajax.php that allows attackers to execute arbitrary SQL comman...

Dec 21, 2023
CVE-2023-51048
9.8

S-CMS v5.0 contains a SQL injection vulnerability in the A_newsauth parameter at /admin/ajax.php that allows attackers to execute arbitrary SQL comman...

Dec 21, 2023
CVE-2023-6145
9.8

This SQL injection vulnerability in Softomi Advanced C2C Marketplace Software allows attackers to execute arbitrary SQL commands against the database....

Dec 21, 2023
CVE-2023-48433
9.8

CVE-2023-48433 allows unauthenticated attackers to execute arbitrary SQL commands against the Online Voting System Project v1.0 database through the u...

Dec 20, 2023
CVE-2023-47990
9.8

This CVE describes a SQL injection vulnerability in CuppaCMS V1.0, specifically in the edit_admin_table.php component. Attackers can execute arbitrary...

Dec 20, 2023
CVE-2023-48384
9.8

ArmorX Global Technology Corporation's ArmorX Spam software has a critical SQL injection vulnerability due to insufficient input validation. Unauthent...

Dec 15, 2023
CVE-2023-48050
9.8

This CVE describes a critical SQL injection vulnerability in the Cams Biometrics Zkteco/eSSL integration module for Odoo HR attendance systems. It all...

Dec 15, 2023
CVE-2023-40954
9.8

A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (web_progress) Odoo module allows remote attackers to execute arbitrary SQL ...

Dec 15, 2023
CVE-2023-48049
9.8

A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search module allows remote attackers to execute arbitrary SQL commands via th...

Dec 15, 2023
CVE-2023-50073
9.8

EmpireCMS v7.5 contains a SQL injection vulnerability in the ftppassword parameter at SetEnews.php. This allows attackers to execute arbitrary SQL com...

Dec 14, 2023
CVE-2023-46348
9.8

This SQL injection vulnerability in SunnyToo sturls module allows attackers to execute arbitrary SQL commands through the StUrls::hookActionDispatcher...

Dec 14, 2023
CVE-2023-48925
9.8

This SQL injection vulnerability in the Buy Addons bavideotab module for PrestaShop allows attackers to execute arbitrary SQL commands through the BaV...

Dec 14, 2023
CVE-2023-49708
9.8

This CVE describes a critical SQL injection vulnerability in the Starshop component for Joomla. Attackers can execute arbitrary SQL commands through t...

Dec 14, 2023
CVE-2023-40629
9.8

CVE-2023-40629 is a critical SQL injection vulnerability in the LMS Lite component for Joomla that allows attackers to execute arbitrary SQL commands....

Dec 14, 2023
CVE-2023-48084
9.8

Nagios XI versions before 5.11.3 contain a SQL injection vulnerability in the bulk modification tool that allows attackers to execute arbitrary SQL co...

Dec 14, 2023
CVE-2023-49934
9.8

This SQL injection vulnerability in SchedMD Slurm 23.11.x allows attackers to execute arbitrary SQL commands against the SlurmDBD database. Organizati...

Dec 14, 2023
CVE-2023-40921
9.8

This SQL injection vulnerability in Common Services soliberte allows attackers to manipulate database queries through the lat and lng parameters in po...

Dec 14, 2023
CVE-2023-49363
9.8

CVE-2023-49363 is a critical SQL injection vulnerability in Rockoa versions before 2.3.3 that allows attackers to execute arbitrary SQL commands. This...

Dec 13, 2023
CVE-2023-49429
9.8

CVE-2023-49429 is a SQL injection vulnerability in Tenda AX9 routers that allows attackers to execute arbitrary SQL commands through the 'mac' paramet...

Dec 7, 2023
CVE-2023-48823
9.8

CVE-2023-48823 is a critical blind SQL injection vulnerability in GaatiTrack Courier Management System 1.0 that allows unauthenticated attackers to ex...

Dec 7, 2023
CVE-2023-5761
9.8

This SQL injection vulnerability in the Burst Statistics WordPress plugin allows unauthenticated attackers to inject malicious SQL queries via the 'ur...

Dec 7, 2023
CVE-2023-46353
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries on PrestaShop installations using the vulnerable 'Product Tag Ico...

Dec 6, 2023
CVE-2023-49371
9.8

RuoYi versions up to 4.6 contain a SQL injection vulnerability in the /system/dept/edit endpoint that allows attackers to execute arbitrary SQL comman...

Dec 1, 2023
CVE-2023-5634
9.8

This SQL injection vulnerability in ArslanSoft Education Portal allows attackers to execute arbitrary SQL commands through the application. It affects...

Dec 1, 2023
CVE-2023-6418
9.8

This SQL injection vulnerability in Voovi Social Networking Script version 1.0 allows remote attackers to execute arbitrary SQL queries via the id par...

Nov 30, 2023
CVE-2023-6416
9.8

This SQL injection vulnerability in Voovi Social Networking Script version 1.0 allows remote attackers to execute arbitrary SQL queries through the em...

Nov 30, 2023
CVE-2023-6414
9.8

This SQL injection vulnerability in Voovi Social Networking Script version 1.0 allows remote attackers to execute arbitrary SQL queries via the id and...

Nov 30, 2023
CVE-2023-6412
9.8

This vulnerability allows remote attackers to execute arbitrary SQL queries through the photo.php file in Voovi Social Networking Script version 1.0. ...

Nov 30, 2023
CVE-2023-6410
9.8

This SQL injection vulnerability in Voovi Social Networking Script version 1.0 allows remote attackers to execute arbitrary SQL queries via the editpr...

Nov 30, 2023
CVE-2022-45135
9.8

This SQL injection vulnerability in Apache Cocoon allows attackers to execute arbitrary SQL commands on affected systems. It affects Apache Cocoon ver...

Nov 30, 2023

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,506 CVEs classified as CWE-89, with 1,938 rated critical and 1,917 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free