CWE-89: SQL Injection
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Yearly Trend
Top Affected Vendors
All SQL Injection CVEs (4,692)
CVE-2023-34487 is a critical SQL injection vulnerability in itsourcecode Online Hotel Management System v1.0.0 that allows attackers to execute arbitr...
Jun 29, 2023Lost and Found Information System v1.0 contains a SQL injection vulnerability in the admin contact information page that allows attackers to execute a...
Jun 28, 2023Jeesite versions before commit 10742d3 contain a SQL injection vulnerability in the ActDao.xml component via the ${businessTable} parameter. This allo...
Jun 22, 2023CVE-2023-33584 is a critical SQL injection vulnerability in Sourcecodester Enrollment System Project V1.0 that allows attackers to bypass authenticati...
Jun 21, 2023This SQL injection vulnerability in WUZHICMS v4.1.0 allows remote attackers to execute arbitrary SQL commands through the checktitle() function in adm...
Jun 20, 2023This SQL injection vulnerability in Marksoft allows attackers to execute arbitrary SQL commands through the Mobile, Login, and API components. Success...
Jun 19, 2023Jeecg-Boot versions 3.5.0 and 3.5.1 contain a SQL injection vulnerability in the id parameter of the /jeecg-boot/jmreport/show interface. This allows ...
Jun 16, 2023Simple Customer Relationship Management 1.0 contains a SQL injection vulnerability in the email parameter that allows attackers to execute arbitrary S...
Jun 16, 2023This is a critical SQL injection vulnerability in Progress MOVEit Transfer that allows unauthenticated attackers to execute arbitrary SQL commands aga...
Jun 16, 2023CVE-2023-32754 is a critical SQL injection vulnerability in Thinking Software Efence's login function that allows unauthenticated attackers to execute...
Jun 16, 2023This CVE describes a SQL injection vulnerability in the 'Length, weight or volume sell' (ailinear) module for PrestaShop versions before 2.4.3. Attack...
Jun 15, 2023This vulnerability allows attackers to execute arbitrary SQL commands through the leocustomajax module in PrestaShop. It affects all websites running ...
Jun 14, 2023This vulnerability allows attackers to execute arbitrary SQL commands on PrestaShop installations using the PostFinance payment module version 17.1.13...
Jun 14, 2023This SQL injection vulnerability in bloofox v0.5.2.1 allows attackers to execute arbitrary SQL commands via the gid parameter in the admin interface. ...
Jun 14, 2023This SQL injection vulnerability in bloofox v0.5.2.1 allows attackers to execute arbitrary SQL commands via the tid parameter in the admin panel. This...
Jun 14, 2023This SQL injection vulnerability in bloofox v0.5.2.1 allows attackers to execute arbitrary SQL commands via the userid parameter in the admin interfac...
Jun 14, 2023CVE-2023-34249 is a critical SQL injection vulnerability in benjjvi/PyBB bulletin board software that allows attackers to execute arbitrary SQL comman...
Jun 13, 2023This SQL injection vulnerability in Satos Mobile allows attackers to execute arbitrary SQL commands by manipulating SOAP parameters. It affects all Sa...
Jun 13, 2023This SQL injection vulnerability in TMT Lockcell allows attackers to execute arbitrary SQL commands on the database. It affects all Lockcell versions ...
Jun 13, 2023CVE-2023-34581 is a critical SQL injection vulnerability in Service Provider Management System v1.0 that allows attackers to execute arbitrary SQL com...
Jun 12, 2023The uListing WordPress plugin contains an SQL injection vulnerability in versions up to 1.6.6 that allows unauthenticated attackers to execute arbitra...
Jun 7, 2023CVE-2023-29632 is a critical SQL injection vulnerability in PrestaShop's jmspagebuilder module that allows attackers to execute arbitrary SQL commands...
Jun 6, 2023CVE-2023-29629 is a critical SQL injection vulnerability in the jmsthemelayout module for PrestaShop. Attackers can execute arbitrary SQL commands thr...
Jun 5, 2023This SQL injection vulnerability in eMedia Consulting simpleRedak allows attackers to execute arbitrary SQL commands via the Activity parameter. Affec...
Jun 2, 2023This SQL injection vulnerability in the City Autocomplete module for PrestaShop allows remote attackers to execute arbitrary SQL commands via frontend...
Jun 2, 2023This is a critical SQL injection vulnerability in ELITE TECHNOLOGY CORP. Web Fax software that allows unauthenticated attackers to execute arbitrary S...
Jun 2, 2023This SQL injection vulnerability in Erikoglu Technology ErMon allows attackers to execute arbitrary SQL commands, potentially leading to command line ...
Jun 2, 2023KramerAV VIA GO² devices running software versions below 4.0.1.1326 contain a SQL injection vulnerability that allows attackers to execute arbitrary ...
May 31, 2023BlueCMS v1.6 contains a SQL injection vulnerability in the search.php file's keywords parameter. This allows attackers to execute arbitrary SQL comman...
May 30, 2023CVE-2022-24627 is an unauthenticated SQL injection vulnerability in AudioCodes Device Manager Express login form. Attackers can execute arbitrary SQL ...
May 29, 2023This vulnerability allows unauthenticated attackers to execute blind SQL injection attacks via HTTP requests to the Store Commander scexportcustomers ...
May 25, 2023This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries via HTTP requests to the Store Commander scquickaccounting module...
May 25, 2023This SQL injection vulnerability in AGT Tech Ceppatron allows attackers to execute arbitrary SQL commands, potentially leading to command line executi...
May 25, 2023This SQL injection vulnerability in Cityboss E-municipality software allows attackers to execute arbitrary SQL commands through user input. It affects...
May 24, 2023This SQL injection vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows attackers to execute arbitrary SQL commands on th...
May 23, 2023CVE-2023-31752 is a critical SQL injection vulnerability in SourceCodester Employee and Visitor Gate Pass Logging System v1.0 that allows attackers to...
May 23, 2023Piwigo 13.6.0 contains a SQL injection vulnerability in the /admin/permalinks.php endpoint that allows attackers to execute arbitrary SQL commands. Th...
May 23, 2023CVE-2023-33338 is a critical SQL injection vulnerability in Old Age Home Management 1.0 that allows attackers to execute arbitrary SQL commands via th...
May 23, 2023CVE-2023-31707 is a critical SQL injection vulnerability in SEMCMS 1.5 that allows attackers to execute arbitrary SQL commands via the Ant_Rponse.php ...
May 19, 2023This vulnerability allows attackers to execute arbitrary SQL commands through the date_from parameter in the admin reports page of Student Study Cente...
May 18, 2023This vulnerability allows attackers to execute arbitrary SQL commands on PrestaShop installations using the cdesigner module version 3.1.9 or earlier....
May 17, 2023IDURAR ERP/CRM v1 contains a SQL injection vulnerability in the login API endpoint that allows attackers to execute arbitrary SQL commands. This affec...
May 16, 2023This vulnerability allows attackers to execute arbitrary SQL commands on PrestaShop websites using the posstaticblocks module version 1.0.0 or earlier...
May 16, 2023This SQL injection vulnerability in Pharmacy Management System v1.0 allows attackers to execute arbitrary SQL commands via the email parameter during ...
May 16, 2023This SQL injection vulnerability in Judging Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the crit_id parameter...
May 15, 2023This vulnerability allows unauthenticated attackers to conduct SQL injection attacks against WordPress sites using the WP Visitor Statistics plugin. A...
May 15, 2023This critical SQL injection vulnerability in PnPSCADA allows unauthenticated attackers to execute arbitrary SQL commands through the hitlogcsv.jsp end...
May 12, 2023A critical SQL injection vulnerability in Judging Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the contestant_...
May 12, 2023CVE-2023-29809 is a critical SQL injection vulnerability in Maximilian Vogt companymaps (cmaps) version 8.0 that allows remote attackers to execute ar...
May 12, 2023PrestaShop possearchproducts module version 1.7 contains a SQL injection vulnerability in the PosSearch::find() function. This allows attackers to exe...
May 12, 2023About SQL Injection (CWE-89)
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Our database tracks 4,692 CVEs classified as CWE-89, with 2,055 rated critical and 1,986 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.
External reference: View CWE-89 on MITRE CWE →
Monitor SQL Injection Vulnerabilities
Get alerted when new SQL Injection CVEs affect your infrastructure.
Start Monitoring Free