CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,677
Total CVEs
2,045
Critical
1,981
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
242
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 130
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,677)

CVE-2023-39647
9.8

This SQL injection vulnerability in the Theme Volty CMS Category Product module for PrestaShop allows unauthenticated attackers to execute arbitrary S...

Oct 3, 2023
CVE-2023-39646
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on PrestaShop installations using the Theme Volty CMS Category C...

Oct 3, 2023
CVE-2023-39649
9.8

This CVE describes an SQL injection vulnerability in the Theme Volty CMS Category Slider module for PrestaShop. Unauthenticated attackers can execute ...

Oct 3, 2023
CVE-2023-43980
9.8

CVE-2023-43980 is a SQL injection vulnerability in Presto Changeo testsitecreator module for PrestaShop. Attackers can execute arbitrary SQL commands ...

Oct 2, 2023
CVE-2023-43739
9.8

This is a SQL injection vulnerability in the 'bookisbn' parameter of cart.php that allows attackers to execute arbitrary SQL commands on the database....

Sep 28, 2023
CVE-2023-44164
9.8

This CVE describes an SQL injection vulnerability in the Email parameter of process_login.php. Attackers can inject malicious SQL commands to manipula...

Sep 28, 2023
CVE-2023-44166
9.8

This is a SQL injection vulnerability in the 'age' parameter of process_registration.php that allows attackers to execute arbitrary SQL commands on th...

Sep 28, 2023
CVE-2023-43013
9.8

Asset Management System v1.0 contains an unauthenticated SQL injection vulnerability in the email parameter of index.php. This allows attackers to ext...

Sep 28, 2023
CVE-2023-5004
9.8

This CVE describes an SQL injection vulnerability in a hospital management system that allows attackers to bypass authentication. Attackers can exploi...

Sep 28, 2023
CVE-2023-30415
9.8

This SQL injection vulnerability in Packers and Movers Management System v1.0 allows attackers to execute arbitrary SQL commands via the id parameter ...

Sep 28, 2023
CVE-2023-38870
9.8

This SQL injection vulnerability in Economizzer allows attackers to execute arbitrary SQL commands via the 'category_id' parameter in the cash book's ...

Sep 28, 2023
CVE-2023-4737
9.8

This SQL injection vulnerability in Hedef Tracking Admin Panel allows attackers to execute arbitrary SQL commands through the admin interface. It affe...

Sep 27, 2023
CVE-2023-35071
9.8

This SQL injection vulnerability in MRV Tech Logging Administration Panel allows attackers to execute arbitrary SQL commands through the web interface...

Sep 27, 2023
CVE-2023-39640
9.8

CVE-2023-39640 is a SQL injection vulnerability in UpLight cookiebanner module for PrestaShop that allows attackers to execute arbitrary SQL commands....

Sep 25, 2023
CVE-2023-43469
9.8

This SQL injection vulnerability in janobe Online Job Portal v.2020 allows remote attackers to execute arbitrary SQL commands via the ForPass.php comp...

Sep 23, 2023
CVE-2023-34576
9.8

This is a critical SQL injection vulnerability in the OpartFAQ module for PrestaShop that allows remote attackers to execute arbitrary SQL commands. A...

Sep 21, 2023
CVE-2023-42279
9.8

Dreamer CMS v4.1.3 contains a SQL injection vulnerability in the model-form-management-field form that allows attackers to execute arbitrary SQL comma...

Sep 21, 2023
CVE-2023-34577
9.8

This CVE describes a critical SQL injection vulnerability in the PrestaShop opartplannedpopup module. Attackers can execute arbitrary SQL commands rem...

Sep 21, 2023
CVE-2023-39675
9.8

This CVE describes a SQL injection vulnerability in the SimpleImportProduct Prestashop module that allows attackers to execute arbitrary SQL commands ...

Sep 20, 2023
CVE-2023-43374
9.8

This SQL injection vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary SQL commands via the id_utente_log parameter in the person...

Sep 20, 2023
CVE-2023-43371
9.8

CVE-2023-43371 is a critical SQL injection vulnerability in Hoteldruid v3.0.5 that allows attackers to execute arbitrary SQL commands via the numcasel...

Sep 20, 2023
CVE-2023-42359
9.8

This SQL injection vulnerability in Exam Form Submission in PHP v1.0 allows remote attackers to execute arbitrary SQL commands via the val-username pa...

Sep 18, 2023
CVE-2023-41887
9.8

CVE-2023-41887 is a critical remote code execution vulnerability in OpenRefine that allows unauthenticated attackers to execute arbitrary code on the ...

Sep 15, 2023
CVE-2023-4833
9.8

This SQL injection vulnerability in Besttem Network Marketing Software allows attackers to execute arbitrary SQL commands on the database. It affects ...

Sep 15, 2023
CVE-2023-4831
9.8

This SQL injection vulnerability in Ncode Ncep allows attackers to execute arbitrary SQL commands on the database. It affects all Ncep installations b...

Sep 15, 2023
CVE-2023-4231
9.8

This SQL injection vulnerability in Cevik Informatics Online Payment System allows attackers to execute arbitrary SQL commands via unvalidated user in...

Sep 15, 2023
CVE-2023-4673
9.8

This SQL injection vulnerability in Sanalogy Turasistan allows attackers to execute arbitrary SQL commands through unvalidated user input. It affects ...

Sep 15, 2023
CVE-2023-39643
9.8

This CVE describes a SQL injection vulnerability in the Bl Modules xmlfeeds PrestaShop module before version 3.9.8. Attackers can exploit the SearchAp...

Sep 15, 2023
CVE-2023-39641
9.8

This SQL injection vulnerability in the psaffiliate PrestaShop module allows attackers to execute arbitrary SQL commands through the PsaffiliateGetaff...

Sep 15, 2023
CVE-2023-42405
9.8

This SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary SQL commands via the 'sort' parameter in multiple...

Sep 14, 2023
CVE-2023-4766
9.8

This SQL injection vulnerability in Movus software allows attackers to execute arbitrary SQL commands by injecting malicious input. It affects all Mov...

Sep 14, 2023
CVE-2023-4832
9.8

This SQL injection vulnerability in Aceka Company Management allows attackers to execute arbitrary SQL commands on the database. All organizations run...

Sep 14, 2023
CVE-2023-40945
9.8

CVE-2023-40945 is a critical SQL injection vulnerability in Sourcecodester Doctor Appointment System 1.0 that allows attackers to execute arbitrary SQ...

Sep 11, 2023
CVE-2023-30058
9.8

CVE-2023-30058 is a SQL injection vulnerability in novel-plus version 3.6.2 that allows attackers to execute arbitrary SQL commands. This affects all ...

Sep 11, 2023
CVE-2023-42268
9.8

Jeecg Boot versions up to 3.5.3 contain a SQL injection vulnerability in the /jeecg-boot/jmreport/show component. This allows attackers to execute arb...

Sep 8, 2023
CVE-2023-41615
9.8

Zoo Management System v1.0 contains SQL injection vulnerabilities in the admin login page that allow attackers to bypass authentication and execute ar...

Sep 8, 2023
CVE-2023-4485
9.8

CVE-2023-4485 is an unauthenticated blind SQL injection vulnerability in ARDEREG Sistema SCADA Central login page. Attackers can execute arbitrary SQL...

Sep 6, 2023
CVE-2023-41507
9.8

Super Store Finder v3.6 contains SQL injection vulnerabilities in its store locator component that allow attackers to execute arbitrary SQL commands v...

Sep 5, 2023
CVE-2023-39361
9.8

CVE-2023-39361 is a critical SQL injection vulnerability in Cacti's graph_view.php that allows unauthenticated attackers to execute arbitrary SQL comm...

Sep 5, 2023
CVE-2023-39654
9.8

This SQL injection vulnerability in abupy allows attackers to execute arbitrary SQL commands through the search_to_symbol_dict function. It affects al...

Sep 5, 2023
CVE-2023-4034
9.8

This SQL injection vulnerability in Digita Information Technology Smartrise Document Management System allows attackers to execute arbitrary SQL comma...

Sep 5, 2023
CVE-2023-4531
9.8

This SQL injection vulnerability in Mestav Software E-commerce Software allows attackers to execute arbitrary SQL commands through unvalidated user in...

Sep 5, 2023
CVE-2023-35068
9.8

This SQL injection vulnerability in BMA Personnel Tracking System allows attackers to execute arbitrary SQL commands through user inputs. It affects a...

Sep 5, 2023
CVE-2023-36361
9.8

Audimexee v14.1.7 contains a SQL injection vulnerability in the p_table_name parameter that allows attackers to execute arbitrary SQL commands. This a...

Sep 5, 2023
CVE-2023-41364
9.8

This SQL injection vulnerability in Tine Groupware allows attackers to execute arbitrary SQL commands through the sort parameter of the /index.php end...

Sep 1, 2023
CVE-2023-41636
9.8

This SQL injection vulnerability in GruppoSCAI RealGimm v1.1.37p38 allows attackers to execute arbitrary SQL commands through the 'Data Richiesta dal'...

Aug 31, 2023
CVE-2023-31714
9.8

CVE-2023-31714 is a critical SQL injection vulnerability in Chitor-CMS that allows attackers to execute arbitrary SQL commands. This affects all Chito...

Aug 30, 2023
CVE-2021-3262
9.8

This CVE describes a critical SQL injection vulnerability in TripSpark VEO Transportation and NovusEDU software. Attackers can inject malicious SQL co...

Aug 29, 2023
CVE-2023-40787
9.8

This CVE describes a SQL injection vulnerability in SpringBlade v3.6.0 where user-submitted parameters are not properly sanitized with quotation marks...

Aug 29, 2023
CVE-2023-39650
9.8

Theme Volty CMS Blog versions up to v4.0.1 contain a SQL injection vulnerability in the id parameter at the /tvcmsblog/single endpoint. This allows at...

Aug 28, 2023

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,677 CVEs classified as CWE-89, with 2,045 rated critical and 1,981 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free