CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,692
Total CVEs
2,055
Critical
1,986
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
242
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 130
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,692)

CVE-2023-34487
9.8

CVE-2023-34487 is a critical SQL injection vulnerability in itsourcecode Online Hotel Management System v1.0.0 that allows attackers to execute arbitr...

Jun 29, 2023
CVE-2023-33592
9.8

Lost and Found Information System v1.0 contains a SQL injection vulnerability in the admin contact information page that allows attackers to execute a...

Jun 28, 2023
CVE-2023-34601
9.8

Jeesite versions before commit 10742d3 contain a SQL injection vulnerability in the ActDao.xml component via the ${businessTable} parameter. This allo...

Jun 22, 2023
CVE-2023-33584
9.8

CVE-2023-33584 is a critical SQL injection vulnerability in Sourcecodester Enrollment System Project V1.0 that allows attackers to bypass authenticati...

Jun 21, 2023
CVE-2020-20413
9.8

This SQL injection vulnerability in WUZHICMS v4.1.0 allows remote attackers to execute arbitrary SQL commands through the checktitle() function in adm...

Jun 20, 2023
CVE-2023-2907
9.8

This SQL injection vulnerability in Marksoft allows attackers to execute arbitrary SQL commands through the Mobile, Login, and API components. Success...

Jun 19, 2023
CVE-2023-34659
9.8

Jeecg-Boot versions 3.5.0 and 3.5.1 contain a SQL injection vulnerability in the id parameter of the /jeecg-boot/jmreport/show interface. This allows ...

Jun 16, 2023
CVE-2023-34548
9.8

Simple Customer Relationship Management 1.0 contains a SQL injection vulnerability in the email parameter that allows attackers to execute arbitrary S...

Jun 16, 2023
CVE-2023-35708
9.8

This is a critical SQL injection vulnerability in Progress MOVEit Transfer that allows unauthenticated attackers to execute arbitrary SQL commands aga...

Jun 16, 2023
CVE-2023-32754
9.8

CVE-2023-32754 is a critical SQL injection vulnerability in Thinking Software Efence's login function that allows unauthenticated attackers to execute...

Jun 16, 2023
CVE-2023-31672
9.8

This CVE describes a SQL injection vulnerability in the 'Length, weight or volume sell' (ailinear) module for PrestaShop versions before 2.4.3. Attack...

Jun 15, 2023
CVE-2023-30150
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the leocustomajax module in PrestaShop. It affects all websites running ...

Jun 14, 2023
CVE-2023-31671
9.8

This vulnerability allows attackers to execute arbitrary SQL commands on PrestaShop installations using the PostFinance payment module version 17.1.13...

Jun 14, 2023
CVE-2023-34751
9.8

This SQL injection vulnerability in bloofox v0.5.2.1 allows attackers to execute arbitrary SQL commands via the gid parameter in the admin interface. ...

Jun 14, 2023
CVE-2023-34753
9.8

This SQL injection vulnerability in bloofox v0.5.2.1 allows attackers to execute arbitrary SQL commands via the tid parameter in the admin panel. This...

Jun 14, 2023
CVE-2023-34755
9.8

This SQL injection vulnerability in bloofox v0.5.2.1 allows attackers to execute arbitrary SQL commands via the userid parameter in the admin interfac...

Jun 14, 2023
CVE-2023-34249
9.8

CVE-2023-34249 is a critical SQL injection vulnerability in benjjvi/PyBB bulletin board software that allows attackers to execute arbitrary SQL comman...

Jun 13, 2023
CVE-2023-35064
9.8

This SQL injection vulnerability in Satos Mobile allows attackers to execute arbitrary SQL commands by manipulating SOAP parameters. It affects all Sa...

Jun 13, 2023
CVE-2023-3047
9.8

This SQL injection vulnerability in TMT Lockcell allows attackers to execute arbitrary SQL commands on the database. It affects all Lockcell versions ...

Jun 13, 2023
CVE-2023-34581
9.8

CVE-2023-34581 is a critical SQL injection vulnerability in Service Provider Management System v1.0 that allows attackers to execute arbitrary SQL com...

Jun 12, 2023
CVE-2021-4340
9.8

The uListing WordPress plugin contains an SQL injection vulnerability in versions up to 1.6.6 that allows unauthenticated attackers to execute arbitra...

Jun 7, 2023
CVE-2023-29632
9.8

CVE-2023-29632 is a critical SQL injection vulnerability in PrestaShop's jmspagebuilder module that allows attackers to execute arbitrary SQL commands...

Jun 6, 2023
CVE-2023-29629
9.8

CVE-2023-29629 is a critical SQL injection vulnerability in the jmsthemelayout module for PrestaShop. Attackers can execute arbitrary SQL commands thr...

Jun 5, 2023
CVE-2023-33762
9.8

This SQL injection vulnerability in eMedia Consulting simpleRedak allows attackers to execute arbitrary SQL commands via the Activity parameter. Affec...

Jun 2, 2023
CVE-2023-30149
9.8

This SQL injection vulnerability in the City Autocomplete module for PrestaShop allows remote attackers to execute arbitrary SQL commands via frontend...

Jun 2, 2023
CVE-2023-28701
9.8

This is a critical SQL injection vulnerability in ELITE TECHNOLOGY CORP. Web Fax software that allows unauthenticated attackers to execute arbitrary S...

Jun 2, 2023
CVE-2023-3000
9.8

This SQL injection vulnerability in Erikoglu Technology ErMon allows attackers to execute arbitrary SQL commands, potentially leading to command line ...

Jun 2, 2023
CVE-2023-33509
9.8

KramerAV VIA GO² devices running software versions below 4.0.1.1326 contain a SQL injection vulnerability that allows attackers to execute arbitrary ...

May 31, 2023
CVE-2023-33734
9.8

BlueCMS v1.6 contains a SQL injection vulnerability in the search.php file's keywords parameter. This allows attackers to execute arbitrary SQL comman...

May 30, 2023
CVE-2022-24627
9.8

CVE-2022-24627 is an unauthenticated SQL injection vulnerability in AudioCodes Device Manager Express login form. Attackers can execute arbitrary SQL ...

May 29, 2023
CVE-2023-33278
9.8

This vulnerability allows unauthenticated attackers to execute blind SQL injection attacks via HTTP requests to the Store Commander scexportcustomers ...

May 25, 2023
CVE-2023-33280
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries via HTTP requests to the Store Commander scquickaccounting module...

May 25, 2023
CVE-2023-2851
9.8

This SQL injection vulnerability in AGT Tech Ceppatron allows attackers to execute arbitrary SQL commands, potentially leading to command line executi...

May 25, 2023
CVE-2023-2750
9.8

This SQL injection vulnerability in Cityboss E-municipality software allows attackers to execute arbitrary SQL commands through user input. It affects...

May 24, 2023
CVE-2023-1508
9.8

This SQL injection vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows attackers to execute arbitrary SQL commands on th...

May 23, 2023
CVE-2023-31752
9.8

CVE-2023-31752 is a critical SQL injection vulnerability in SourceCodester Employee and Visitor Gate Pass Logging System v1.0 that allows attackers to...

May 23, 2023
CVE-2023-33361
9.8

Piwigo 13.6.0 contains a SQL injection vulnerability in the /admin/permalinks.php endpoint that allows attackers to execute arbitrary SQL commands. Th...

May 23, 2023
CVE-2023-33338
9.8

CVE-2023-33338 is a critical SQL injection vulnerability in Old Age Home Management 1.0 that allows attackers to execute arbitrary SQL commands via th...

May 23, 2023
CVE-2023-31707
9.8

CVE-2023-31707 is a critical SQL injection vulnerability in SEMCMS 1.5 that allows attackers to execute arbitrary SQL commands via the Ant_Rponse.php ...

May 19, 2023
CVE-2023-29985
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the date_from parameter in the admin reports page of Student Study Cente...

May 18, 2023
CVE-2023-30191
9.8

This vulnerability allows attackers to execute arbitrary SQL commands on PrestaShop installations using the cdesigner module version 3.1.9 or earlier....

May 17, 2023
CVE-2023-27742
9.8

IDURAR ERP/CRM v1 contains a SQL injection vulnerability in the login API endpoint that allows attackers to execute arbitrary SQL commands. This affec...

May 16, 2023
CVE-2023-30189
9.8

This vulnerability allows attackers to execute arbitrary SQL commands on PrestaShop websites using the posstaticblocks module version 1.0.0 or earlier...

May 16, 2023
CVE-2023-31519
9.8

This SQL injection vulnerability in Pharmacy Management System v1.0 allows attackers to execute arbitrary SQL commands via the email parameter during ...

May 16, 2023
CVE-2023-30245
9.8

This SQL injection vulnerability in Judging Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the crit_id parameter...

May 15, 2023
CVE-2023-0600
9.8

This vulnerability allows unauthenticated attackers to conduct SQL injection attacks against WordPress sites using the WP Visitor Statistics plugin. A...

May 15, 2023
CVE-2023-1934
9.8

This critical SQL injection vulnerability in PnPSCADA allows unauthenticated attackers to execute arbitrary SQL commands through the hitlogcsv.jsp end...

May 12, 2023
CVE-2023-30246
9.8

A critical SQL injection vulnerability in Judging Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the contestant_...

May 12, 2023
CVE-2023-29809
9.8

CVE-2023-29809 is a critical SQL injection vulnerability in Maximilian Vogt companymaps (cmaps) version 8.0 that allows remote attackers to execute ar...

May 12, 2023
CVE-2023-30192
9.8

PrestaShop possearchproducts module version 1.7 contains a SQL injection vulnerability in the PosSearch::find() function. This allows attackers to exe...

May 12, 2023

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,692 CVEs classified as CWE-89, with 2,055 rated critical and 1,986 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free