CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,438
Total CVEs
1,895
Critical
1,892
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
241
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Oretnom23 125
2 Phpgurukul 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,438)

CVE-2022-36276
9.9

CVE-2022-36276 is a critical SQL injection vulnerability in TCMAN GIM v8.0.1 that allows remote attackers to execute arbitrary SQL commands via the 'S...

Oct 4, 2023
CVE-2023-30839
9.9

This CVE describes a SQL injection vulnerability in PrestaShop e-commerce software that allows back-office users to perform unauthorized database oper...

Apr 25, 2023
CVE-2022-38074
9.9

CVE-2022-38074 is a SQL injection vulnerability in the VeronaLabs WP Statistics WordPress plugin that allows authenticated attackers to execute arbitr...

Mar 13, 2023
CVE-2021-43362
9.9

This SQL injection vulnerability in MedData HBYS allows attackers to execute arbitrary SQL commands on the database. It affects all HBYS installations...

Nov 16, 2021
CVE-2021-42369
9.9

CVE-2021-42369 is a SQL injection vulnerability in Imagicle Application Suite for Cisco UC, allowing low-privileged users to inject SQL statements via...

Oct 14, 2021
CVE-2021-23230
9.9

A SQL injection vulnerability in the OPCUA interface of Gallagher Command Centre allows remote unprivileged operators to modify databases undetected. ...

Jun 11, 2021
CVE-2026-28501
9.8

CVE-2026-28501 is an unauthenticated SQL injection vulnerability in WWBN AVideo that allows attackers to execute arbitrary SQL commands without authen...

Mar 6, 2026
CVE-2026-27847
9.8

This vulnerability allows SQL injection through TLS-SRP handshake parameters, enabling attackers to inject known credentials into the database. Succes...

Feb 25, 2026
CVE-2026-21410
9.8

CVE-2026-21410 is a SQL injection vulnerability in SAT MasterSCADA BUK-TS web interface that allows attackers to execute arbitrary SQL commands. Succe...

Feb 24, 2026
CVE-2026-26198
9.8

CVE-2026-26198 is a critical SQL injection vulnerability in Ormar ORM for Python that allows attackers to execute arbitrary SQL queries. Unauthorized ...

Feb 24, 2026
CVE-2026-24494
9.8

An unauthenticated SQL injection vulnerability in Order Up Online Ordering System 1.0 allows attackers to execute arbitrary SQL commands via the store...

Feb 23, 2026
CVE-2019-25459
9.8

CVE-2019-25459 is an unauthenticated SQL injection vulnerability in Web Ofisi Emlak V2 real estate software. Attackers can inject SQL code through mul...

Feb 22, 2026
CVE-2025-10970
9.8

This is a critical SQL injection vulnerability in Kolay Software Inc.'s Talentics platform that allows attackers to execute arbitrary SQL commands. It...

Feb 20, 2026
CVE-2025-70152
9.8

CVE-2025-70152 is an unauthenticated SQL injection vulnerability in the Community Project Scholars Tracking System 1.0 that allows attackers to execut...

Feb 18, 2026
CVE-2025-70149
9.8

CodeAstro Membership Management System 1.0 contains a SQL injection vulnerability in the print_membership_card.php file via the ID parameter. This all...

Feb 18, 2026
CVE-2025-70981
9.8

CVE-2025-70981 is a critical SQL injection vulnerability in CordysCRM 1.4.1 that allows attackers to execute arbitrary SQL commands through the depart...

Feb 12, 2026
CVE-2025-10969
9.8

This SQL injection vulnerability in Farktor Software's E-Commerce Package allows attackers to execute arbitrary SQL commands through the application. ...

Feb 12, 2026
CVE-2026-25993
9.8

CVE-2026-25993 is a second-order SQL injection vulnerability in EverShop eCommerce platform that allows attackers to execute arbitrary SQL commands. A...

Feb 10, 2026
CVE-2025-6830
9.8

This SQL injection vulnerability in Xpoda Studio allows attackers to execute arbitrary SQL commands on the database. All users running Xpoda Studio ve...

Feb 9, 2026
CVE-2026-25544
9.8

This is a critical SQL injection vulnerability in Payload CMS versions before 3.73.0 that allows unauthenticated attackers to extract sensitive data a...

Feb 6, 2026
CVE-2026-21643
9.8

An unauthenticated SQL injection vulnerability in Fortinet FortiClientEMS allows attackers to execute arbitrary SQL commands via crafted HTTP requests...

Feb 6, 2026
CVE-2025-5329
9.8

This SQL injection vulnerability in Martcode Software's Delta Course Automation allows attackers to execute arbitrary SQL commands on the database. Al...

Feb 4, 2026
CVE-2026-25240
9.8

This SQL injection vulnerability in PEAR's user::maintains() function allows attackers to execute arbitrary SQL commands when role filters are provide...

Feb 3, 2026
CVE-2026-25241
9.8

This CVE describes an unauthenticated SQL injection vulnerability in PEAR's package retrieval endpoint. Attackers can execute arbitrary SQL commands b...

Feb 3, 2026
CVE-2026-25238
9.8

A SQL injection vulnerability in PEAR's bug subscription deletion feature allows attackers to execute arbitrary SQL commands by manipulating email val...

Feb 3, 2026
CVE-2026-25236
9.8

This CVE describes a SQL injection vulnerability in PEAR, a PHP component framework, where unsafe literal substitution in karma queries allows attacke...

Feb 3, 2026
CVE-2026-25234
9.8

This SQL injection vulnerability in PEAR's category deletion function allows attackers with category manager access to execute arbitrary SQL commands....

Feb 3, 2026
CVE-2025-63624
9.8

This SQL injection vulnerability in Shandong Kede Electronics' IoT smart water meter monitoring platform allows remote attackers to execute arbitrary ...

Feb 3, 2026
CVE-2025-57529
9.8

CVE-2025-57529 is a critical SQL injection vulnerability in YouDataSum CPAS Audit Management System that allows remote unauthenticated attackers to ex...

Feb 3, 2026
CVE-2025-5319
9.8

This SQL injection vulnerability in DIGITA Efficiency Management System allows attackers to execute arbitrary SQL commands on the database. All system...

Feb 3, 2026
CVE-2025-69562
9.8

CVE-2025-69562 is a critical SQL injection vulnerability in code-projects Mobile Shop Management System 1.0 that allows attackers to execute arbitrary...

Jan 27, 2026
CVE-2025-69563
9.8

CVE-2025-69563 is a critical SQL injection vulnerability in code-projects Mobile Shop Management System 1.0 that allows attackers to execute arbitrary...

Jan 27, 2026
CVE-2025-49055
9.8

This SQL injection vulnerability in the WP Lead Capturing Pages WordPress plugin allows attackers to execute arbitrary SQL commands on the database. I...

Jan 22, 2026
CVE-2026-0610
9.8

A SQL injection vulnerability in Devolutions Server's remote-sessions component allows attackers to execute arbitrary SQL commands. This affects Devol...

Jan 19, 2026
CVE-2025-70892
9.8

CVE-2025-70892 is a critical SQL injection vulnerability in Phpgurukul Cyber Cafe Management System v1.0 that allows attackers to execute arbitrary SQ...

Jan 15, 2026
CVE-2025-14598
9.8

BeeS Software Solutions BET Portal contains a critical SQL injection vulnerability in its login functionality, allowing attackers to execute arbitrary...

Jan 9, 2026
CVE-2025-61246
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the proId parameter in master/review_action.php. It affects all installa...

Jan 8, 2026
CVE-2025-61548
9.8

This SQL injection vulnerability in Print Shop Pro WebDesk allows remote attackers to execute arbitrary SQL commands by manipulating the hfInventoryDi...

Jan 8, 2026
CVE-2025-67921
9.8

This SQL injection vulnerability in the VanKarWai Lobo WordPress theme allows attackers to execute arbitrary SQL commands through specially crafted in...

Jan 8, 2026
CVE-2025-67928
9.8

This SQL injection vulnerability in the Automotive Listings WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It af...

Jan 8, 2026
CVE-2025-22728
9.8

This SQL injection vulnerability in the Workreap WordPress theme plugin allows attackers to execute arbitrary SQL commands on the database. It affects...

Jan 8, 2026
CVE-2025-23993
9.8

This SQL injection vulnerability in the Felan Framework WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It affect...

Jan 8, 2026
CVE-2025-22713
9.8

This SQL injection vulnerability in the WooCommerce Orders & Customers Exporter plugin allows attackers to execute arbitrary SQL commands on WordPress...

Jan 8, 2026
CVE-2026-21875
9.8

ClipBucket v5 versions 5.5.2-#187 and below contain a blind SQL injection vulnerability in the comment functionality. Attackers can exploit this by in...

Jan 8, 2026
CVE-2025-59389
9.8

An SQL injection vulnerability in Hyper Data Protector allows remote attackers to execute unauthorized SQL commands. This affects all systems running ...

Jan 2, 2026
CVE-2025-65125
9.8

This SQL injection vulnerability in the online-movie-booking system allows attackers to execute arbitrary SQL commands through the movie_details.php e...

Jan 2, 2026
CVE-2022-50694
9.8

This SQL injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco systems allows attackers to bypass authentication and potentially access sensitive d...

Dec 30, 2025
CVE-2025-68990
9.8

This SQL injection vulnerability in the BWL Pro Voting Manager WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It...

Dec 30, 2025
CVE-2024-44065
9.8

CVE-2024-44065 is a critical SQL injection vulnerability in Cloudlog v2.6.15 that allows attackers to execute arbitrary SQL commands through the qsore...

Dec 26, 2025
CVE-2025-68590
9.8

This SQL injection vulnerability in the CRM Perks Integration for Contact Form 7 HubSpot WordPress plugin allows attackers to execute arbitrary SQL co...

Dec 24, 2025

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,438 CVEs classified as CWE-89, with 1,895 rated critical and 1,892 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free