CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,666
Total CVEs
2,037
Critical
1,978
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
242
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 130
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,666)

CVE-2022-45135
9.8

This SQL injection vulnerability in Apache Cocoon allows attackers to execute arbitrary SQL commands on affected systems. It affects Apache Cocoon ver...

Nov 30, 2023
CVE-2023-46349
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries on PrestaShop installations using the vulnerable 'Product Catalog...

Nov 27, 2023
CVE-2023-46575
9.8

A SQL injection vulnerability in Meshery allows remote attackers to execute arbitrary SQL commands through the 'order' parameter, potentially leading ...

Nov 24, 2023
CVE-2023-3377
9.8

This SQL injection vulnerability in Veribilim Software Computer Veribase allows attackers to execute arbitrary SQL commands through specially crafted ...

Nov 23, 2023
CVE-2023-46357
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries on PrestaShop installations using the 'Cross Selling in Modal Car...

Nov 22, 2023
CVE-2023-45377
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on PrestaShop installations using the Chronopost Official module...

Nov 22, 2023
CVE-2023-2889
9.8

This SQL injection vulnerability in Veon Computer Service Tracking Software allows attackers to execute arbitrary SQL commands on the database. It aff...

Nov 22, 2023
CVE-2023-5047
9.8

This SQL injection vulnerability in DRD Fleet Leasing DRDrive allows attackers to execute arbitrary SQL commands through the application. It affects a...

Nov 22, 2023
CVE-2023-37924
9.8

CVE-2023-37924 is an SQL injection vulnerability in Apache Submarine's login functionality that allows attackers to bypass authentication and gain una...

Nov 22, 2023
CVE-2023-5652
9.8

CVE-2023-5652 is a critical SQL injection vulnerability in the WP Hotel Booking WordPress plugin. Unauthenticated attackers can exploit missing author...

Nov 20, 2023
CVE-2023-5640
9.8

This CVE describes a critical SQL injection vulnerability in the Article Analytics WordPress plugin. Unauthenticated attackers can exploit it by sendi...

Nov 20, 2023
CVE-2023-46700
9.8

This is a critical SQL injection vulnerability in LuxCal Web Calendar that allows remote unauthenticated attackers to execute arbitrary SQL commands. ...

Nov 20, 2023
CVE-2023-45387
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on PrestaShop websites using the 'Product Catalog Export PRO' mod...

Nov 17, 2023
CVE-2023-48078
9.8

This SQL injection vulnerability in Simple CRUD Functionality v1.0 allows attackers to execute arbitrary SQL commands through the 'title' parameter in...

Nov 17, 2023
CVE-2021-35437
9.8

This SQL injection vulnerability in LMXCMS v1.4 allows attackers to execute arbitrary SQL commands through the TagsAction.class component. Attackers c...

Nov 16, 2023
CVE-2023-47445
9.8

CVE-2023-47445 is a critical SQL injection vulnerability in Pre-School Enrollment System version 1.0 that allows attackers to execute arbitrary SQL co...

Nov 15, 2023
CVE-2023-43979
9.8

This SQL injection vulnerability in ETS Soft ybc_blog allows attackers to execute arbitrary SQL commands through the getPosts() function. It affects a...

Nov 15, 2023
CVE-2023-39796
9.8

This SQL injection vulnerability in WBCE CMS's miniform module allows remote unauthenticated attackers to execute arbitrary SQL commands via the DB_RE...

Nov 10, 2023
CVE-2023-46800
9.8

Online Matrimonial Project v1.0 has unauthenticated SQL injection vulnerabilities in the view_profile.php resource. Attackers can execute arbitrary SQ...

Nov 7, 2023
CVE-2023-46793
9.8

Online Matrimonial Project v1.0 contains unauthenticated SQL injection vulnerabilities in the register() function's 'day' parameter, allowing attacker...

Nov 7, 2023
CVE-2023-46787
9.8

Online Matrimonial Project v1.0 contains unauthenticated SQL injection vulnerabilities in the auth/auth.php resource. Attackers can execute arbitrary ...

Nov 7, 2023
CVE-2023-46789
9.8

Online Matrimonial Project v1.0 has unauthenticated SQL injection vulnerabilities in the functions.php resource. Attackers can execute arbitrary SQL c...

Nov 7, 2023
CVE-2023-46785
9.8

Online Matrimonial Project v1.0 contains unauthenticated SQL injection vulnerabilities in the partner_preference.php resource. Attackers can execute a...

Nov 7, 2023
CVE-2023-46679
9.8

Online Job Portal v1.0 has unauthenticated SQL injection vulnerabilities in the 'txt_uname_email' parameter of index.php, allowing attackers to execut...

Nov 7, 2023
CVE-2023-46677
9.8

Online Job Portal v1.0 has unauthenticated SQL injection vulnerabilities in the sign-up.php file, specifically in the 'txt_uname' parameter. This allo...

Nov 7, 2023
CVE-2023-33481
9.8

RemoteClinic 2.0 contains a time-based blind SQL injection vulnerability in the patients/index.php 'start' parameter that allows attackers to extract ...

Nov 7, 2023
CVE-2023-42283
9.8

This is a critical SQL injection vulnerability in Tyk Gateway's API endpoint that allows attackers to execute arbitrary SQL queries without authentica...

Nov 7, 2023
CVE-2023-38382
9.8

This SQL injection vulnerability in the WordPress Subscribe to Category plugin allows attackers to execute arbitrary SQL commands on the database. It ...

Nov 6, 2023
CVE-2023-40609
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Contact Form 7 Custom Validation pl...

Nov 6, 2023
CVE-2023-45001
9.8

This SQL injection vulnerability in the Seriously Simple Stats WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It...

Nov 6, 2023
CVE-2023-45055
9.8

This SQL injection vulnerability in the InspireUI MStore API WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It a...

Nov 6, 2023
CVE-2023-45074
9.8

This SQL injection vulnerability in the Advanced Page Visit Counter WordPress plugin allows attackers to execute arbitrary SQL commands on the databas...

Nov 6, 2023
CVE-2023-27605
9.8

This SQL injection vulnerability in the WP Reroute Email WordPress plugin allows attackers to execute arbitrary SQL commands. It affects all WordPress...

Nov 6, 2023
CVE-2023-33924
9.8

This SQL injection vulnerability in the Felix Welberg SIS Handball WordPress plugin allows attackers to execute arbitrary SQL commands on the database...

Nov 6, 2023
CVE-2022-45373
9.8

This SQL injection vulnerability in the Slimstat Analytics WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It aff...

Nov 6, 2023
CVE-2022-46860
9.8

This SQL injection vulnerability in the WordPress Short URL plugin allows attackers to execute arbitrary SQL commands on the database. It affects all ...

Nov 6, 2023
CVE-2022-47428
9.8

This SQL injection vulnerability in the WpDevArt Booking Calendar plugin for WordPress allows attackers to execute arbitrary SQL commands on the datab...

Nov 6, 2023
CVE-2022-47432
9.8

This SQL injection vulnerability in the WordPress Shortcode IMDB plugin allows attackers to execute arbitrary SQL commands on the database. It affects...

Nov 6, 2023
CVE-2023-46981
9.8

A SQL injection vulnerability in Novel-Plus v4.2.0 allows remote attackers to execute arbitrary SQL commands via the sort parameter in the /common/log...

Nov 5, 2023
CVE-2023-40922
9.8

This SQL injection vulnerability in kerawen e-commerce software allows attackers to execute arbitrary SQL commands through the ocs_id_cart parameter. ...

Nov 4, 2023
CVE-2023-36529
9.8

This SQL injection vulnerability in the Houzez Real Estate WordPress theme allows attackers to execute arbitrary SQL commands on the database. It affe...

Nov 3, 2023
CVE-2022-46818
9.8

CVE-2022-46818 is an SQL injection vulnerability in the WordPress 'Email posts to subscribers' plugin. It allows attackers to execute arbitrary SQL co...

Nov 3, 2023
CVE-2022-45805
9.8

This SQL injection vulnerability in the Paytm Payment Gateway WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It ...

Nov 3, 2023
CVE-2022-46859
9.8

This SQL injection vulnerability in the Spiffy Calendar WordPress plugin allows attackers to execute arbitrary SQL commands. It affects all versions u...

Nov 3, 2023
CVE-2022-47445
9.8

This SQL injection vulnerability in the WordPress Be POPIA Compliant plugin allows attackers to execute arbitrary SQL commands on the database. It aff...

Nov 3, 2023
CVE-2023-26015
9.8

This SQL injection vulnerability in the MapPress Maps for WordPress plugin allows authenticated attackers to execute arbitrary SQL commands on the dat...

Nov 3, 2023
CVE-2022-47588
9.8

This SQL injection vulnerability in the Simple Photo Gallery WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It a...

Nov 3, 2023
CVE-2023-46954
9.8

This SQL injection vulnerability in RelativityOne allows remote attackers to execute arbitrary SQL commands via the name parameter. Attackers can pote...

Nov 3, 2023
CVE-2023-45338
9.8

Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the routers/add-ticket.php endpoint. Attackers can execute arbit...

Nov 2, 2023
CVE-2023-45346
9.8

Online Food Ordering System v1.0 contains unauthenticated SQL injection vulnerabilities in the routers/user-router.php resource. Attackers can execute...

Nov 2, 2023

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,666 CVEs classified as CWE-89, with 2,037 rated critical and 1,978 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free