CWE-89: SQL Injection
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Yearly Trend
Top Affected Vendors
All SQL Injection CVEs (4,666)
This SQL injection vulnerability in Apache Cocoon allows attackers to execute arbitrary SQL commands on affected systems. It affects Apache Cocoon ver...
Nov 30, 2023This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries on PrestaShop installations using the vulnerable 'Product Catalog...
Nov 27, 2023A SQL injection vulnerability in Meshery allows remote attackers to execute arbitrary SQL commands through the 'order' parameter, potentially leading ...
Nov 24, 2023This SQL injection vulnerability in Veribilim Software Computer Veribase allows attackers to execute arbitrary SQL commands through specially crafted ...
Nov 23, 2023This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries on PrestaShop installations using the 'Cross Selling in Modal Car...
Nov 22, 2023This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on PrestaShop installations using the Chronopost Official module...
Nov 22, 2023This SQL injection vulnerability in Veon Computer Service Tracking Software allows attackers to execute arbitrary SQL commands on the database. It aff...
Nov 22, 2023This SQL injection vulnerability in DRD Fleet Leasing DRDrive allows attackers to execute arbitrary SQL commands through the application. It affects a...
Nov 22, 2023CVE-2023-37924 is an SQL injection vulnerability in Apache Submarine's login functionality that allows attackers to bypass authentication and gain una...
Nov 22, 2023CVE-2023-5652 is a critical SQL injection vulnerability in the WP Hotel Booking WordPress plugin. Unauthenticated attackers can exploit missing author...
Nov 20, 2023This CVE describes a critical SQL injection vulnerability in the Article Analytics WordPress plugin. Unauthenticated attackers can exploit it by sendi...
Nov 20, 2023This is a critical SQL injection vulnerability in LuxCal Web Calendar that allows remote unauthenticated attackers to execute arbitrary SQL commands. ...
Nov 20, 2023This vulnerability allows unauthenticated attackers to perform SQL injection attacks on PrestaShop websites using the 'Product Catalog Export PRO' mod...
Nov 17, 2023This SQL injection vulnerability in Simple CRUD Functionality v1.0 allows attackers to execute arbitrary SQL commands through the 'title' parameter in...
Nov 17, 2023This SQL injection vulnerability in LMXCMS v1.4 allows attackers to execute arbitrary SQL commands through the TagsAction.class component. Attackers c...
Nov 16, 2023CVE-2023-47445 is a critical SQL injection vulnerability in Pre-School Enrollment System version 1.0 that allows attackers to execute arbitrary SQL co...
Nov 15, 2023This SQL injection vulnerability in ETS Soft ybc_blog allows attackers to execute arbitrary SQL commands through the getPosts() function. It affects a...
Nov 15, 2023This SQL injection vulnerability in WBCE CMS's miniform module allows remote unauthenticated attackers to execute arbitrary SQL commands via the DB_RE...
Nov 10, 2023Online Matrimonial Project v1.0 has unauthenticated SQL injection vulnerabilities in the view_profile.php resource. Attackers can execute arbitrary SQ...
Nov 7, 2023Online Matrimonial Project v1.0 contains unauthenticated SQL injection vulnerabilities in the register() function's 'day' parameter, allowing attacker...
Nov 7, 2023Online Matrimonial Project v1.0 contains unauthenticated SQL injection vulnerabilities in the auth/auth.php resource. Attackers can execute arbitrary ...
Nov 7, 2023Online Matrimonial Project v1.0 has unauthenticated SQL injection vulnerabilities in the functions.php resource. Attackers can execute arbitrary SQL c...
Nov 7, 2023Online Matrimonial Project v1.0 contains unauthenticated SQL injection vulnerabilities in the partner_preference.php resource. Attackers can execute a...
Nov 7, 2023Online Job Portal v1.0 has unauthenticated SQL injection vulnerabilities in the 'txt_uname_email' parameter of index.php, allowing attackers to execut...
Nov 7, 2023Online Job Portal v1.0 has unauthenticated SQL injection vulnerabilities in the sign-up.php file, specifically in the 'txt_uname' parameter. This allo...
Nov 7, 2023RemoteClinic 2.0 contains a time-based blind SQL injection vulnerability in the patients/index.php 'start' parameter that allows attackers to extract ...
Nov 7, 2023This is a critical SQL injection vulnerability in Tyk Gateway's API endpoint that allows attackers to execute arbitrary SQL queries without authentica...
Nov 7, 2023This SQL injection vulnerability in the WordPress Subscribe to Category plugin allows attackers to execute arbitrary SQL commands on the database. It ...
Nov 6, 2023This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Contact Form 7 Custom Validation pl...
Nov 6, 2023This SQL injection vulnerability in the Seriously Simple Stats WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It...
Nov 6, 2023This SQL injection vulnerability in the InspireUI MStore API WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It a...
Nov 6, 2023This SQL injection vulnerability in the Advanced Page Visit Counter WordPress plugin allows attackers to execute arbitrary SQL commands on the databas...
Nov 6, 2023This SQL injection vulnerability in the WP Reroute Email WordPress plugin allows attackers to execute arbitrary SQL commands. It affects all WordPress...
Nov 6, 2023This SQL injection vulnerability in the Felix Welberg SIS Handball WordPress plugin allows attackers to execute arbitrary SQL commands on the database...
Nov 6, 2023This SQL injection vulnerability in the Slimstat Analytics WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It aff...
Nov 6, 2023This SQL injection vulnerability in the WordPress Short URL plugin allows attackers to execute arbitrary SQL commands on the database. It affects all ...
Nov 6, 2023This SQL injection vulnerability in the WpDevArt Booking Calendar plugin for WordPress allows attackers to execute arbitrary SQL commands on the datab...
Nov 6, 2023This SQL injection vulnerability in the WordPress Shortcode IMDB plugin allows attackers to execute arbitrary SQL commands on the database. It affects...
Nov 6, 2023A SQL injection vulnerability in Novel-Plus v4.2.0 allows remote attackers to execute arbitrary SQL commands via the sort parameter in the /common/log...
Nov 5, 2023This SQL injection vulnerability in kerawen e-commerce software allows attackers to execute arbitrary SQL commands through the ocs_id_cart parameter. ...
Nov 4, 2023This SQL injection vulnerability in the Houzez Real Estate WordPress theme allows attackers to execute arbitrary SQL commands on the database. It affe...
Nov 3, 2023CVE-2022-46818 is an SQL injection vulnerability in the WordPress 'Email posts to subscribers' plugin. It allows attackers to execute arbitrary SQL co...
Nov 3, 2023This SQL injection vulnerability in the Paytm Payment Gateway WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It ...
Nov 3, 2023This SQL injection vulnerability in the Spiffy Calendar WordPress plugin allows attackers to execute arbitrary SQL commands. It affects all versions u...
Nov 3, 2023This SQL injection vulnerability in the WordPress Be POPIA Compliant plugin allows attackers to execute arbitrary SQL commands on the database. It aff...
Nov 3, 2023This SQL injection vulnerability in the MapPress Maps for WordPress plugin allows authenticated attackers to execute arbitrary SQL commands on the dat...
Nov 3, 2023This SQL injection vulnerability in the Simple Photo Gallery WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It a...
Nov 3, 2023This SQL injection vulnerability in RelativityOne allows remote attackers to execute arbitrary SQL commands via the name parameter. Attackers can pote...
Nov 3, 2023Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the routers/add-ticket.php endpoint. Attackers can execute arbit...
Nov 2, 2023Online Food Ordering System v1.0 contains unauthenticated SQL injection vulnerabilities in the routers/user-router.php resource. Attackers can execute...
Nov 2, 2023About SQL Injection (CWE-89)
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Our database tracks 4,666 CVEs classified as CWE-89, with 2,037 rated critical and 1,978 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.
External reference: View CWE-89 on MITRE CWE →
Monitor SQL Injection Vulnerabilities
Get alerted when new SQL Injection CVEs affect your infrastructure.
Start Monitoring Free