CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,687
Total CVEs
2,055
Critical
1,981
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
242
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 130
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,687)

CVE-2023-39652
9.8

This CVE describes a SQL injection vulnerability in the theme volty tvcmsvideotab module for PrestaShop. Attackers can exploit this to execute arbitra...

Aug 28, 2023
CVE-2023-39560
9.8

ECTouch v2 contains a SQL injection vulnerability in the $arr['id'] parameter at \default\helpers\insert.php. This allows attackers to execute arbitra...

Aug 28, 2023
CVE-2023-40748
9.8

PHPJabbers Food Delivery Script 3.0 contains a SQL injection vulnerability in the 'q' parameter of index.php that allows attackers to execute arbitrar...

Aug 28, 2023
CVE-2023-39807
9.8

This SQL injection vulnerability in NVK iBSG v3.5 allows attackers to execute arbitrary SQL commands through the a_passwd parameter in the user regist...

Aug 21, 2023
CVE-2023-39850
9.8

Schoolmate v1.3 contains SQL injection vulnerabilities in the DeleteFunctions.php file via the $courseid and $teacherid parameters. Attackers can exec...

Aug 15, 2023
CVE-2023-39852
9.8

CVE-2023-39852 is a SQL injection vulnerability in Doctormms v1.0 that allows attackers to execute arbitrary SQL commands via the $userid parameter in...

Aug 15, 2023
CVE-2023-37847
9.8

CVE-2023-37847 is a SQL injection vulnerability in novel-plus v3.6.2 that allows attackers to execute arbitrary SQL commands. This affects all systems...

Aug 14, 2023
CVE-2020-36034
9.8

This CVE describes a SQL injection vulnerability in the School Faculty Scheduling System version 1.0 that allows remote attackers to execute arbitrary...

Aug 11, 2023
CVE-2023-39805
9.8

CVE-2023-39805 is a SQL injection vulnerability in iCMS v7.0.16 that allows attackers to execute arbitrary SQL commands via the where parameter in adm...

Aug 10, 2023
CVE-2023-36311
9.8

This SQL injection vulnerability in PHPJabbers Document Creator v1.0 allows attackers to execute arbitrary SQL commands via the 'column' parameter in ...

Aug 10, 2023
CVE-2023-37068
9.8

CVE-2023-37068 is a critical SQL injection vulnerability in Code-Projects Gym Management System V1.0 that allows remote attackers to execute arbitrary...

Aug 9, 2023
CVE-2023-34545
9.8

A critical SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to execute arbitrary SQL commands through the p parameter or search URL...

Aug 9, 2023
CVE-2023-3386
9.8

This SQL injection vulnerability in the a2 Camera Trap Tracking System allows attackers to execute arbitrary SQL commands on the database. It affects ...

Aug 8, 2023
CVE-2023-3651
9.8

This SQL injection vulnerability in Digital Ant E-Commerce Software allows attackers to execute arbitrary SQL commands through user input. It affects ...

Aug 8, 2023
CVE-2023-3716
9.8

This SQL injection vulnerability in Oduyo Online Collection Software allows attackers to execute arbitrary SQL commands by injecting malicious input. ...

Aug 8, 2023
CVE-2023-37682
9.8

Judging Management System v1.0 contains a SQL injection vulnerability in the deductScores.php endpoint via the id parameter. This allows attackers to ...

Aug 8, 2023
CVE-2023-3717
9.8

This SQL injection vulnerability in Farmakom Remote Administration Console allows attackers to execute arbitrary SQL commands on the database. It affe...

Aug 8, 2023
CVE-2023-37372
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary SQL queries on RUGGEDCOM CROSSBOW server databases. It affects all ver...

Aug 8, 2023
CVE-2023-3898
9.8

This SQL injection vulnerability in mAyaNet E-Commerce Software allows attackers to execute arbitrary SQL commands through unvalidated user input. All...

Aug 8, 2023
CVE-2023-34476
9.8

This SQL injection vulnerability in ProForms Basic Joomla extension allows attackers to execute arbitrary SQL commands through unsanitized user input....

Aug 7, 2023
CVE-2023-38044
9.8

This SQL injection vulnerability in HikaShop for Joomla allows attackers to execute arbitrary SQL commands through improper input sanitization. It aff...

Aug 7, 2023
CVE-2023-23757
9.8

CVE-2023-23757 is a critical SQL injection vulnerability in the BA Gallery Joomla extension that allows attackers to execute arbitrary SQL commands. T...

Aug 7, 2023
CVE-2023-33367
9.8

This SQL injection vulnerability in Control ID IDSecure allows unauthenticated attackers to write PHP files to the server's root directory, leading to...

Aug 5, 2023
CVE-2023-39551
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the search functionality in PHPGurukul Online Security Guards Hiring Sys...

Aug 4, 2023
CVE-2023-33665
9.8

CVE-2023-33665 is a SQL injection vulnerability in ai-dev aitable's /includes/ajax.php component that allows attackers to execute arbitrary SQL comman...

Aug 4, 2023
CVE-2023-36213
9.8

This SQL injection vulnerability in MotoCMS v3.4.3 allows remote attackers to execute arbitrary SQL commands via the keyword parameter in the search f...

Aug 3, 2023
CVE-2023-38954
9.8

CVE-2023-38954 is a critical SQL injection vulnerability in ZKTeco BioAccess IVS v3.3.1 that allows attackers to execute arbitrary SQL commands on the...

Aug 3, 2023
CVE-2023-37771
9.8

Art Gallery Management System v1.0 has a SQL injection vulnerability in the product.php page's cid parameter that allows attackers to execute arbitrar...

Jul 31, 2023
CVE-2023-34635
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the username field of the login page in Wifi Soft Unibox Administration ...

Jul 31, 2023
CVE-2020-21662
9.8

This is a critical SQL injection vulnerability in YunyeCMS 2.0.2 that allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-Fo...

Jul 31, 2023
CVE-2023-26859
9.8

This SQL injection vulnerability in PrestaShop's SendinBlue module allows remote attackers to execute arbitrary SQL commands via the ajaxOrderTracking...

Jul 26, 2023
CVE-2023-35088
9.8

This CVE describes an SQL injection vulnerability in Apache InLong's toAuditCkSql method where user-controlled parameters (groupId, streamId, auditId,...

Jul 25, 2023
CVE-2023-35066
9.8

This SQL injection vulnerability in Infodrom Software's E-Invoice Approval System allows attackers to execute arbitrary SQL commands through unvalidat...

Jul 25, 2023
CVE-2023-31753
9.8

This SQL injection vulnerability in eNdonesia 8.7 allows attackers to execute arbitrary SQL commands through the 'rid=' parameter in diskusi.php. Atta...

Jul 20, 2023
CVE-2023-37165
9.8

Millhouse-Project v1.414 contains a SQL injection vulnerability in the /add_post_sql.php component that allows remote attackers to execute arbitrary c...

Jul 20, 2023
CVE-2023-30153
9.8

This SQL injection vulnerability in the Payplug module for PrestaShop allows remote attackers to execute arbitrary SQL commands via the ajax.php front...

Jul 18, 2023
CVE-2021-37522
9.8

This CVE describes a SQL injection vulnerability in Locke-Bot 2.0.2, a Discord bot, that allows remote attackers to execute arbitrary SQL commands. At...

Jul 18, 2023
CVE-2023-3376
9.8

This SQL injection vulnerability in Digital Strategy Zekiweb allows attackers to execute arbitrary SQL commands through unvalidated user input. It aff...

Jul 17, 2023
CVE-2023-2963
9.8

This SQL injection vulnerability in Oliva Expertise EKS allows attackers to execute arbitrary SQL commands on the database. It affects all Oliva Exper...

Jul 17, 2023
CVE-2023-30151
9.8

A SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop allows remote attackers to execute arbitrary SQL commands via the '...

Jul 13, 2023
CVE-2023-35070
9.8

This SQL injection vulnerability in VegaGroup Web Collection allows attackers to execute arbitrary SQL commands on the database. It affects all Web Co...

Jul 13, 2023
CVE-2023-1547
9.8

This SQL injection vulnerability in Elra Parkmatik allows attackers to execute arbitrary SQL commands through SOAP parameter tampering. Successful exp...

Jul 13, 2023
CVE-2023-37628
9.8

CVE-2023-37628 is a critical SQL injection vulnerability in Online Piggery Management System 1.0 that allows attackers to execute arbitrary SQL comman...

Jul 12, 2023
CVE-2023-37627
9.8

CVE-2023-37627 is a critical SQL injection vulnerability in Code-projects Online Restaurant Management System 1.0 that allows attackers to bypass auth...

Jul 12, 2023
CVE-2023-26861
9.8

CVE-2023-26861 is a critical SQL injection vulnerability in the Viva Wallet payment module for PrestaShop. Attackers can exploit this to execute arbit...

Jul 11, 2023
CVE-2023-3045
9.8

This SQL injection vulnerability in Tise Technology Parking Web Report allows attackers to execute arbitrary SQL commands on the database. It affects ...

Jul 10, 2023
CVE-2023-2852
9.8

This SQL injection vulnerability in Softmed SelfPatron allows attackers to execute arbitrary SQL commands on the database. It affects all SelfPatron i...

Jul 10, 2023
CVE-2023-2046
9.8

This SQL injection vulnerability in Yontem Informatics Vehicle Tracking System allows attackers to execute arbitrary SQL commands on the database. It ...

Jul 10, 2023
CVE-2023-27845
9.8

This SQL injection vulnerability in PrestaShop's Kerawen OCS module allows remote attackers to execute arbitrary SQL commands via specific components....

Jul 7, 2023
CVE-2023-3490
9.8

This SQL injection vulnerability in fossbilling allows attackers to execute arbitrary SQL commands through the application. It affects all users runni...

Jun 30, 2023

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,687 CVEs classified as CWE-89, with 2,055 rated critical and 1,981 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free