CWE-89: SQL Injection
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Yearly Trend
Top Affected Vendors
All SQL Injection CVEs (4,687)
This CVE describes a SQL injection vulnerability in the theme volty tvcmsvideotab module for PrestaShop. Attackers can exploit this to execute arbitra...
Aug 28, 2023ECTouch v2 contains a SQL injection vulnerability in the $arr['id'] parameter at \default\helpers\insert.php. This allows attackers to execute arbitra...
Aug 28, 2023PHPJabbers Food Delivery Script 3.0 contains a SQL injection vulnerability in the 'q' parameter of index.php that allows attackers to execute arbitrar...
Aug 28, 2023This SQL injection vulnerability in NVK iBSG v3.5 allows attackers to execute arbitrary SQL commands through the a_passwd parameter in the user regist...
Aug 21, 2023Schoolmate v1.3 contains SQL injection vulnerabilities in the DeleteFunctions.php file via the $courseid and $teacherid parameters. Attackers can exec...
Aug 15, 2023CVE-2023-39852 is a SQL injection vulnerability in Doctormms v1.0 that allows attackers to execute arbitrary SQL commands via the $userid parameter in...
Aug 15, 2023CVE-2023-37847 is a SQL injection vulnerability in novel-plus v3.6.2 that allows attackers to execute arbitrary SQL commands. This affects all systems...
Aug 14, 2023This CVE describes a SQL injection vulnerability in the School Faculty Scheduling System version 1.0 that allows remote attackers to execute arbitrary...
Aug 11, 2023CVE-2023-39805 is a SQL injection vulnerability in iCMS v7.0.16 that allows attackers to execute arbitrary SQL commands via the where parameter in adm...
Aug 10, 2023This SQL injection vulnerability in PHPJabbers Document Creator v1.0 allows attackers to execute arbitrary SQL commands via the 'column' parameter in ...
Aug 10, 2023CVE-2023-37068 is a critical SQL injection vulnerability in Code-Projects Gym Management System V1.0 that allows remote attackers to execute arbitrary...
Aug 9, 2023A critical SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to execute arbitrary SQL commands through the p parameter or search URL...
Aug 9, 2023This SQL injection vulnerability in the a2 Camera Trap Tracking System allows attackers to execute arbitrary SQL commands on the database. It affects ...
Aug 8, 2023This SQL injection vulnerability in Digital Ant E-Commerce Software allows attackers to execute arbitrary SQL commands through user input. It affects ...
Aug 8, 2023This SQL injection vulnerability in Oduyo Online Collection Software allows attackers to execute arbitrary SQL commands by injecting malicious input. ...
Aug 8, 2023Judging Management System v1.0 contains a SQL injection vulnerability in the deductScores.php endpoint via the id parameter. This allows attackers to ...
Aug 8, 2023This SQL injection vulnerability in Farmakom Remote Administration Console allows attackers to execute arbitrary SQL commands on the database. It affe...
Aug 8, 2023This vulnerability allows unauthenticated remote attackers to execute arbitrary SQL queries on RUGGEDCOM CROSSBOW server databases. It affects all ver...
Aug 8, 2023This SQL injection vulnerability in mAyaNet E-Commerce Software allows attackers to execute arbitrary SQL commands through unvalidated user input. All...
Aug 8, 2023This SQL injection vulnerability in ProForms Basic Joomla extension allows attackers to execute arbitrary SQL commands through unsanitized user input....
Aug 7, 2023This SQL injection vulnerability in HikaShop for Joomla allows attackers to execute arbitrary SQL commands through improper input sanitization. It aff...
Aug 7, 2023CVE-2023-23757 is a critical SQL injection vulnerability in the BA Gallery Joomla extension that allows attackers to execute arbitrary SQL commands. T...
Aug 7, 2023This SQL injection vulnerability in Control ID IDSecure allows unauthenticated attackers to write PHP files to the server's root directory, leading to...
Aug 5, 2023This vulnerability allows attackers to execute arbitrary SQL commands through the search functionality in PHPGurukul Online Security Guards Hiring Sys...
Aug 4, 2023CVE-2023-33665 is a SQL injection vulnerability in ai-dev aitable's /includes/ajax.php component that allows attackers to execute arbitrary SQL comman...
Aug 4, 2023This SQL injection vulnerability in MotoCMS v3.4.3 allows remote attackers to execute arbitrary SQL commands via the keyword parameter in the search f...
Aug 3, 2023CVE-2023-38954 is a critical SQL injection vulnerability in ZKTeco BioAccess IVS v3.3.1 that allows attackers to execute arbitrary SQL commands on the...
Aug 3, 2023Art Gallery Management System v1.0 has a SQL injection vulnerability in the product.php page's cid parameter that allows attackers to execute arbitrar...
Jul 31, 2023This vulnerability allows attackers to execute arbitrary SQL commands through the username field of the login page in Wifi Soft Unibox Administration ...
Jul 31, 2023This is a critical SQL injection vulnerability in YunyeCMS 2.0.2 that allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-Fo...
Jul 31, 2023This SQL injection vulnerability in PrestaShop's SendinBlue module allows remote attackers to execute arbitrary SQL commands via the ajaxOrderTracking...
Jul 26, 2023This CVE describes an SQL injection vulnerability in Apache InLong's toAuditCkSql method where user-controlled parameters (groupId, streamId, auditId,...
Jul 25, 2023This SQL injection vulnerability in Infodrom Software's E-Invoice Approval System allows attackers to execute arbitrary SQL commands through unvalidat...
Jul 25, 2023This SQL injection vulnerability in eNdonesia 8.7 allows attackers to execute arbitrary SQL commands through the 'rid=' parameter in diskusi.php. Atta...
Jul 20, 2023Millhouse-Project v1.414 contains a SQL injection vulnerability in the /add_post_sql.php component that allows remote attackers to execute arbitrary c...
Jul 20, 2023This SQL injection vulnerability in the Payplug module for PrestaShop allows remote attackers to execute arbitrary SQL commands via the ajax.php front...
Jul 18, 2023This CVE describes a SQL injection vulnerability in Locke-Bot 2.0.2, a Discord bot, that allows remote attackers to execute arbitrary SQL commands. At...
Jul 18, 2023This SQL injection vulnerability in Digital Strategy Zekiweb allows attackers to execute arbitrary SQL commands through unvalidated user input. It aff...
Jul 17, 2023This SQL injection vulnerability in Oliva Expertise EKS allows attackers to execute arbitrary SQL commands on the database. It affects all Oliva Exper...
Jul 17, 2023A SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop allows remote attackers to execute arbitrary SQL commands via the '...
Jul 13, 2023This SQL injection vulnerability in VegaGroup Web Collection allows attackers to execute arbitrary SQL commands on the database. It affects all Web Co...
Jul 13, 2023This SQL injection vulnerability in Elra Parkmatik allows attackers to execute arbitrary SQL commands through SOAP parameter tampering. Successful exp...
Jul 13, 2023CVE-2023-37628 is a critical SQL injection vulnerability in Online Piggery Management System 1.0 that allows attackers to execute arbitrary SQL comman...
Jul 12, 2023CVE-2023-37627 is a critical SQL injection vulnerability in Code-projects Online Restaurant Management System 1.0 that allows attackers to bypass auth...
Jul 12, 2023CVE-2023-26861 is a critical SQL injection vulnerability in the Viva Wallet payment module for PrestaShop. Attackers can exploit this to execute arbit...
Jul 11, 2023This SQL injection vulnerability in Tise Technology Parking Web Report allows attackers to execute arbitrary SQL commands on the database. It affects ...
Jul 10, 2023This SQL injection vulnerability in Softmed SelfPatron allows attackers to execute arbitrary SQL commands on the database. It affects all SelfPatron i...
Jul 10, 2023This SQL injection vulnerability in Yontem Informatics Vehicle Tracking System allows attackers to execute arbitrary SQL commands on the database. It ...
Jul 10, 2023This SQL injection vulnerability in PrestaShop's Kerawen OCS module allows remote attackers to execute arbitrary SQL commands via specific components....
Jul 7, 2023This SQL injection vulnerability in fossbilling allows attackers to execute arbitrary SQL commands through the application. It affects all users runni...
Jun 30, 2023About SQL Injection (CWE-89)
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Our database tracks 4,687 CVEs classified as CWE-89, with 2,055 rated critical and 1,981 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.
External reference: View CWE-89 on MITRE CWE →
Monitor SQL Injection Vulnerabilities
Get alerted when new SQL Injection CVEs affect your infrastructure.
Start Monitoring Free