CWE-89: SQL Injection
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Yearly Trend
Top Affected Vendors
All SQL Injection CVEs (4,672)
Online Food Ordering System v1.0 contains unauthenticated SQL injection vulnerabilities in the routers/user-router.php resource. Attackers can execute...
Nov 2, 2023Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the '*_balance' parameter of routers/user-router.php. Attackers ...
Nov 2, 2023Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the 'status' parameter of routers/edit-orders.php. Attackers can...
Nov 2, 2023Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the routers/router.php resource, allowing attackers to execute a...
Nov 2, 2023Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the 'phone' parameter of routers/details-router.php, allowing at...
Nov 2, 2023Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the phone parameter of the registration router. Attackers can ex...
Nov 2, 2023Online Food Ordering System v1.0 contains unauthenticated SQL injection vulnerabilities in the routers/add-users.php endpoint. Attackers can exploit t...
Nov 2, 2023Online Bus Booking System v1.0 contains unauthenticated SQL injection vulnerabilities in the login.php file, allowing attackers to execute arbitrary S...
Nov 2, 2023Online Bus Booking System v1.0 contains unauthenticated SQL injection vulnerabilities in the bus_info.php file. Attackers can execute arbitrary SQL co...
Nov 2, 2023Online Bus Booking System v1.0 contains unauthenticated SQL injection vulnerabilities in the bus_info.php file's 'date' parameter. Attackers can execu...
Nov 2, 2023Online Examination System v1.0 contains unauthenticated SQL injection vulnerabilities in the feed.php resource's email parameter. Attackers can execut...
Nov 2, 2023This SQL injection vulnerability in wuzhicms v4.1.0 allows remote attackers to execute arbitrary SQL commands through the database backup functionalit...
Nov 1, 2023This SQL injection vulnerability in the WordPress User Activity Log plugin allows attackers to execute arbitrary SQL commands on the database. It affe...
Oct 31, 2023This SQL injection vulnerability in WordPress Contact Form Entries plugin allows authenticated attackers to execute arbitrary SQL commands on the data...
Oct 31, 2023This SQL injection vulnerability in WooCommerce Product Vendors allows attackers to execute arbitrary SQL commands on affected WordPress sites. It aff...
Oct 31, 2023This CVE describes an unauthenticated SQL injection vulnerability in the GamiPress WordPress plugin. Attackers can execute arbitrary SQL commands with...
Oct 31, 2023CVE-2023-36263 is a critical SQL injection vulnerability in the Prestashop opartlimitquantity module. Attackers can execute arbitrary SQL commands via...
Oct 31, 2023This SQL injection vulnerability in PrestaShop themevolty modules allows remote attackers to execute arbitrary SQL commands through multiple component...
Oct 31, 2023This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries on PrestaShop installations using the CSV Feeds PRO module. Attac...
Oct 31, 2023This SQL injection vulnerability in TRtek Software Education Portal allows attackers to execute arbitrary SQL commands by injecting malicious input. I...
Oct 27, 2023This CVE describes a critical SQL injection vulnerability in D-Link DAR-7000 Online Behavior Audit Gateway. Attackers can exploit the editrole.php com...
Oct 26, 2023Online Art Gallery v1.0 contains unauthenticated SQL injection vulnerabilities in the 'lnm' parameter of header.php. Attackers can execute arbitrary S...
Oct 26, 2023This vulnerability allows attackers to execute arbitrary SQL commands through the 'id' parameter in the Packers and Movers Management System. Attacker...
Oct 26, 2023This CVE describes a critical SQL injection vulnerability in PHPGurukul Nipah Virus Testing Management System v1.0 that allows remote attackers to exe...
Oct 25, 2023This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on PrestaShop installations using the vulnerable 'Step by Step p...
Oct 25, 2023Unauthenticated SQL injection in IDAttend's IDWeb application allows attackers to extract or modify all database data without credentials. This affect...
Oct 25, 2023Unauthenticated SQL injection vulnerability in IDAttend's IDWeb application allows attackers to extract or modify all database data without authentica...
Oct 25, 2023This vulnerability allows unauthenticated attackers to perform SQL injection attacks on IDAttend's IDWeb application. Attackers can extract or modify ...
Oct 25, 2023This vulnerability allows unauthenticated attackers to perform SQL injection attacks against IDAttend's IDWeb application. Attackers can extract or mo...
Oct 25, 2023This vulnerability allows unauthenticated attackers to perform SQL injection attacks against IDAttend's IDWeb application. Attackers can extract or mo...
Oct 25, 2023Unauthenticated attackers can execute arbitrary SQL queries against IDAttend's IDWeb application, potentially extracting or modifying all database dat...
Oct 25, 2023This vulnerability allows unauthenticated attackers to perform SQL injection attacks against IDAttend's IDWeb application. Attackers can extract or mo...
Oct 25, 2023This SQL injection vulnerability in Sitolog sitologapplicationconnect v7.8.a and earlier allows attackers to execute arbitrary SQL commands via the /a...
Oct 20, 2023This CVE describes a SQL injection vulnerability in DM Concept configurator for PrestaShop. Attackers can exploit the ConfiguratorAttachment::getAttac...
Oct 19, 2023This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries on PrestaShop installations using the 'Rotator Img' module. Attac...
Oct 19, 2023This SQL injection vulnerability in the WordPress ChatBot plugin allows unauthenticated attackers to execute arbitrary SQL queries through the $strid ...
Oct 19, 2023This SQL injection vulnerability in Best Courier Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'id' parameter in /e...
Oct 18, 2023CVE-2023-46007 is a critical SQL injection vulnerability in Best Courier Management System 1.0 that allows attackers to execute arbitrary SQL commands...
Oct 18, 2023CVE-2023-45951 is a SQL injection vulnerability in lylme_spage v1.7.0 that allows attackers to execute arbitrary SQL commands via the $userip paramete...
Oct 17, 2023This vulnerability allows attackers to execute arbitrary SQL commands on D-Link DAR-7000 Online Behavior Audit Gateway devices via the /log/mailrecvvi...
Oct 17, 2023This SQL injection vulnerability in the extratabspro PrestaShop module allows unauthenticated attackers to execute arbitrary SQL commands. All PrestaS...
Oct 17, 2023This SQL injection vulnerability in Phpgurukul's User Registration & Login and User Management System allows attackers to bypass authentication and ex...
Oct 16, 2023This CVE describes SQL injection vulnerabilities in the AfterMail module for PrestaShop that allow remote attackers to execute arbitrary SQL commands....
Oct 14, 2023This CVE describes a critical SQL injection vulnerability in Plixer Scrutinizer's csvExportReport endpoint. Unauthenticated attackers can execute arbi...
Oct 12, 2023This SQL injection vulnerability in Biltay Technology Kayisi allows attackers to execute arbitrary SQL commands, potentially leading to command line e...
Oct 12, 2023Hansun CMS v1.0 contains a SQL injection vulnerability in the /ajax/ajax_login.ashx component that allows attackers to execute arbitrary SQL commands....
Oct 9, 2023This SQL injection vulnerability in the Turna Advertising Administration Panel allows attackers to execute arbitrary SQL commands by injecting malicio...
Oct 6, 2023This SQL injection vulnerability in Prixan prixanconnect allows attackers to execute arbitrary SQL commands through the importProducts() function. It ...
Oct 5, 2023This SQL injection vulnerability in the KnowBand SuperCheckout module allows remote attackers to execute arbitrary SQL commands via crafted requests t...
Oct 5, 2023CVE-2023-3038 is a critical SQL injection vulnerability in HelpDezk Community version 1.1.10 that allows remote attackers to execute arbitrary SQL que...
Oct 4, 2023About SQL Injection (CWE-89)
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Our database tracks 4,672 CVEs classified as CWE-89, with 2,042 rated critical and 1,979 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.
External reference: View CWE-89 on MITRE CWE →
Monitor SQL Injection Vulnerabilities
Get alerted when new SQL Injection CVEs affect your infrastructure.
Start Monitoring Free