CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,672
Total CVEs
2,042
Critical
1,979
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
242
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 130
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,672)

CVE-2023-45346
9.8

Online Food Ordering System v1.0 contains unauthenticated SQL injection vulnerabilities in the routers/user-router.php resource. Attackers can execute...

Nov 2, 2023
CVE-2023-45344
9.8

Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the '*_balance' parameter of routers/user-router.php. Attackers ...

Nov 2, 2023
CVE-2023-45334
9.8

Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the 'status' parameter of routers/edit-orders.php. Attackers can...

Nov 2, 2023
CVE-2023-45336
9.8

Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the routers/router.php resource, allowing attackers to execute a...

Nov 2, 2023
CVE-2023-45340
9.8

Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the 'phone' parameter of routers/details-router.php, allowing at...

Nov 2, 2023
CVE-2023-45342
9.8

Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the phone parameter of the registration router. Attackers can ex...

Nov 2, 2023
CVE-2023-45325
9.8

Online Food Ordering System v1.0 contains unauthenticated SQL injection vulnerabilities in the routers/add-users.php endpoint. Attackers can exploit t...

Nov 2, 2023
CVE-2023-45018
9.8

Online Bus Booking System v1.0 contains unauthenticated SQL injection vulnerabilities in the login.php file, allowing attackers to execute arbitrary S...

Nov 2, 2023
CVE-2023-45012
9.8

Online Bus Booking System v1.0 contains unauthenticated SQL injection vulnerabilities in the bus_info.php file. Attackers can execute arbitrary SQL co...

Nov 2, 2023
CVE-2023-45015
9.8

Online Bus Booking System v1.0 contains unauthenticated SQL injection vulnerabilities in the bus_info.php file's 'date' parameter. Attackers can execu...

Nov 2, 2023
CVE-2023-45111
9.8

Online Examination System v1.0 contains unauthenticated SQL injection vulnerabilities in the feed.php resource's email parameter. Attackers can execut...

Nov 2, 2023
CVE-2023-46482
9.8

This SQL injection vulnerability in wuzhicms v4.1.0 allows remote attackers to execute arbitrary SQL commands through the database backup functionalit...

Nov 1, 2023
CVE-2023-37966
9.8

This SQL injection vulnerability in the WordPress User Activity Log plugin allows attackers to execute arbitrary SQL commands on the database. It affe...

Oct 31, 2023
CVE-2023-31212
9.8

This SQL injection vulnerability in WordPress Contact Form Entries plugin allows authenticated attackers to execute arbitrary SQL commands on the data...

Oct 31, 2023
CVE-2023-35879
9.8

This SQL injection vulnerability in WooCommerce Product Vendors allows attackers to execute arbitrary SQL commands on affected WordPress sites. It aff...

Oct 31, 2023
CVE-2023-24000
9.8

This CVE describes an unauthenticated SQL injection vulnerability in the GamiPress WordPress plugin. Attackers can execute arbitrary SQL commands with...

Oct 31, 2023
CVE-2023-36263
9.8

CVE-2023-36263 is a critical SQL injection vulnerability in the Prestashop opartlimitquantity module. Attackers can execute arbitrary SQL commands via...

Oct 31, 2023
CVE-2023-27846
9.8

This SQL injection vulnerability in PrestaShop themevolty modules allows remote attackers to execute arbitrary SQL commands through multiple component...

Oct 31, 2023
CVE-2023-46356
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries on PrestaShop installations using the CSV Feeds PRO module. Attac...

Oct 31, 2023
CVE-2023-5807
9.8

This SQL injection vulnerability in TRtek Software Education Portal allows attackers to execute arbitrary SQL commands by injecting malicious input. I...

Oct 27, 2023
CVE-2023-42406
9.8

This CVE describes a critical SQL injection vulnerability in D-Link DAR-7000 Online Behavior Audit Gateway. Attackers can exploit the editrole.php com...

Oct 26, 2023
CVE-2023-44267
9.8

Online Art Gallery v1.0 contains unauthenticated SQL injection vulnerabilities in the 'lnm' parameter of header.php. Attackers can execute arbitrary S...

Oct 26, 2023
CVE-2023-46435
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the 'id' parameter in the Packers and Movers Management System. Attacker...

Oct 26, 2023
CVE-2023-46584
9.8

This CVE describes a critical SQL injection vulnerability in PHPGurukul Nipah Virus Testing Management System v1.0 that allows remote attackers to exe...

Oct 25, 2023
CVE-2023-46347
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on PrestaShop installations using the vulnerable 'Step by Step p...

Oct 25, 2023
CVE-2023-26581
9.8

Unauthenticated SQL injection in IDAttend's IDWeb application allows attackers to extract or modify all database data without credentials. This affect...

Oct 25, 2023
CVE-2023-26583
9.8

Unauthenticated SQL injection vulnerability in IDAttend's IDWeb application allows attackers to extract or modify all database data without authentica...

Oct 25, 2023
CVE-2023-27254
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on IDAttend's IDWeb application. Attackers can extract or modify ...

Oct 25, 2023
CVE-2023-27260
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks against IDAttend's IDWeb application. Attackers can extract or mo...

Oct 25, 2023
CVE-2023-27262
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks against IDAttend's IDWeb application. Attackers can extract or mo...

Oct 25, 2023
CVE-2023-26568
9.8

Unauthenticated attackers can execute arbitrary SQL queries against IDAttend's IDWeb application, potentially extracting or modifying all database dat...

Oct 25, 2023
CVE-2023-26572
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks against IDAttend's IDWeb application. Attackers can extract or mo...

Oct 25, 2023
CVE-2023-37824
9.8

This SQL injection vulnerability in Sitolog sitologapplicationconnect v7.8.a and earlier allows attackers to execute arbitrary SQL commands via the /a...

Oct 20, 2023
CVE-2023-43986
9.8

This CVE describes a SQL injection vulnerability in DM Concept configurator for PrestaShop. Attackers can exploit the ConfiguratorAttachment::getAttac...

Oct 19, 2023
CVE-2023-45379
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries on PrestaShop installations using the 'Rotator Img' module. Attac...

Oct 19, 2023
CVE-2023-5204
9.8

This SQL injection vulnerability in the WordPress ChatBot plugin allows unauthenticated attackers to execute arbitrary SQL queries through the $strid ...

Oct 19, 2023
CVE-2023-46005
9.8

This SQL injection vulnerability in Best Courier Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'id' parameter in /e...

Oct 18, 2023
CVE-2023-46007
9.8

CVE-2023-46007 is a critical SQL injection vulnerability in Best Courier Management System 1.0 that allows attackers to execute arbitrary SQL commands...

Oct 18, 2023
CVE-2023-45951
9.8

CVE-2023-45951 is a SQL injection vulnerability in lylme_spage v1.7.0 that allows attackers to execute arbitrary SQL commands via the $userip paramete...

Oct 17, 2023
CVE-2023-44694
9.8

This vulnerability allows attackers to execute arbitrary SQL commands on D-Link DAR-7000 Online Behavior Audit Gateway devices via the /log/mailrecvvi...

Oct 17, 2023
CVE-2023-45386
9.8

This SQL injection vulnerability in the extratabspro PrestaShop module allows unauthenticated attackers to execute arbitrary SQL commands. All PrestaS...

Oct 17, 2023
CVE-2023-40852
9.8

This SQL injection vulnerability in Phpgurukul's User Registration & Login and User Management System allows attackers to bypass authentication and ex...

Oct 16, 2023
CVE-2023-30154
9.8

This CVE describes SQL injection vulnerabilities in the AfterMail module for PrestaShop that allow remote attackers to execute arbitrary SQL commands....

Oct 14, 2023
CVE-2023-41262
9.8

This CVE describes a critical SQL injection vulnerability in Plixer Scrutinizer's csvExportReport endpoint. Unauthenticated attackers can execute arbi...

Oct 12, 2023
CVE-2023-5045
9.8

This SQL injection vulnerability in Biltay Technology Kayisi allows attackers to execute arbitrary SQL commands, potentially leading to command line e...

Oct 12, 2023
CVE-2023-43899
9.8

Hansun CMS v1.0 contains a SQL injection vulnerability in the /ajax/ajax_login.ashx component that allows attackers to execute arbitrary SQL commands....

Oct 9, 2023
CVE-2023-4530
9.8

This SQL injection vulnerability in the Turna Advertising Administration Panel allows attackers to execute arbitrary SQL commands by injecting malicio...

Oct 6, 2023
CVE-2023-40920
9.8

This SQL injection vulnerability in Prixan prixanconnect allows attackers to execute arbitrary SQL commands through the importProducts() function. It ...

Oct 5, 2023
CVE-2023-44024
9.8

This SQL injection vulnerability in the KnowBand SuperCheckout module allows remote attackers to execute arbitrary SQL commands via crafted requests t...

Oct 5, 2023
CVE-2023-3038
9.8

CVE-2023-3038 is a critical SQL injection vulnerability in HelpDezk Community version 1.1.10 that allows remote attackers to execute arbitrary SQL que...

Oct 4, 2023

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,672 CVEs classified as CWE-89, with 2,042 rated critical and 1,979 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free