CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,699
Total CVEs
2,059
Critical
1,989
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
242
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 130
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,699)

CVE-2023-29863
9.8

Medical Systems Co. Medisys Weblab Products v19.4.03 contains a SQL injection vulnerability in the WSDL files via the tem:statement parameter. This al...

May 11, 2023
CVE-2023-30092
9.8

CVE-2023-30092 is a critical SQL injection vulnerability in SourceCodester Online Pizza Ordering System v1.0 that allows attackers to execute arbitrar...

May 8, 2023
CVE-2020-23966
9.8

This SQL injection vulnerability in Victor CMS 1.0 allows attackers to execute arbitrary SQL commands through the post parameter in GET requests to /p...

May 8, 2023
CVE-2022-4118
9.8

This SQL injection vulnerability in the Bitcoin/AltCoin Payment Gateway WordPress plugin allows authenticated users to execute arbitrary SQL commands ...

May 8, 2023
CVE-2023-30018
9.8

Judging Management System v1.0 contains a SQL injection vulnerability in the review_se_result.php endpoint that allows attackers to execute arbitrary ...

May 8, 2023
CVE-2023-30242
9.8

CVE-2023-30242 is a critical SQL injection vulnerability in NS-ASG v6.3's /admin/add_ikev2.php component that allows attackers to execute arbitrary SQ...

May 5, 2023
CVE-2023-30203
9.8

Judging Management System v1.0 contains a SQL injection vulnerability in the result_sheet.php file via the event_id parameter. This allows attackers t...

May 4, 2023
CVE-2023-30077
9.8

Judging Management System v1.0 contains a SQL injection vulnerability in the review_result.php endpoint via the mainevent_id parameter. This allows at...

May 4, 2023
CVE-2023-30204
9.8

Judging Management System v1.0 contains a SQL injection vulnerability in the edit_judge.php endpoint via the judge_id parameter. This allows attackers...

May 3, 2023
CVE-2023-1730
9.8

CVE-2023-1730 is a critical SQL injection vulnerability in the SupportCandy WordPress plugin. Unauthenticated attackers can exploit this to execute ar...

May 2, 2023
CVE-2023-26781
9.8

CVE-2023-26781 is a critical SQL injection vulnerability in mccms 2.6 that allows remote attackers to execute arbitrary SQL commands through the Autho...

Apr 28, 2023
CVE-2023-26813
9.8

This is a critical SQL injection vulnerability in wangmarket CMS that allows remote attackers to execute arbitrary SQL commands. Attackers can manipul...

Apr 28, 2023
CVE-2023-30211
9.8

OURPHP versions up to 7.2.0 contain a SQL injection vulnerability in the background/admin interface. This allows attackers to execute arbitrary SQL co...

Apr 26, 2023
CVE-2023-27843
9.8

This CVE describes a SQL injection vulnerability in the PrestaShop 'Ask for a Quote' module versions 5.4.2 and earlier. It allows remote attackers to ...

Apr 26, 2023
CVE-2012-5872
9.8

CVE-2012-5872 is a blind SQL injection vulnerability in ARC (ARC2) RDF store software that allows attackers to execute arbitrary SQL commands through ...

Apr 26, 2023
CVE-2023-26865
9.8

This is a critical SQL injection vulnerability in the Bdroppy module for PrestaShop that allows remote attackers to execute arbitrary SQL commands. At...

Apr 24, 2023
CVE-2023-23753
9.8

CVE-2023-23753 is a critical SQL injection vulnerability in the Visforms Base Package extension for Joomla 3. Attackers can exploit this to execute ar...

Apr 23, 2023
CVE-2023-30076
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the print_judges.php endpoint in Judging Management System v1.0. Attacke...

Apr 20, 2023
CVE-2023-27844
9.8

This SQL injection vulnerability in PrestaShopleurlrewrite v1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the Dispatch...

Apr 17, 2023
CVE-2023-1723
9.8

This SQL injection vulnerability in Veragroup Mobile Assistant allows attackers to execute arbitrary SQL commands on the database. It affects all Mobi...

Apr 17, 2023
CVE-2023-1863
9.8

This SQL injection vulnerability in Eskom Water Metering Software allows attackers to execute arbitrary SQL commands, potentially leading to command l...

Apr 14, 2023
CVE-2023-29622
9.8

Purchase Order Management v1.0 contains a SQL injection vulnerability in the admin login page that allows attackers to execute arbitrary SQL commands ...

Apr 14, 2023
CVE-2023-27667
9.8

Auto Dealer Management System v1.0 contains a SQL injection vulnerability that allows attackers to execute arbitrary SQL commands through user input. ...

Apr 13, 2023
CVE-2023-27779
9.8

AM Presencia v3.7.3 contains a SQL injection vulnerability in the login form's user parameter, allowing attackers to execute arbitrary SQL commands. T...

Apr 13, 2023
CVE-2023-29598
9.8

CVE-2023-29598 is a SQL injection vulnerability in lmxcms v1.4.1 that allows attackers to execute arbitrary SQL commands via the setbook parameter at ...

Apr 13, 2023
CVE-2022-31890
9.8

This CVE describes a SQL injection vulnerability in osTicket-plugins that allows attackers to execute arbitrary SQL commands via the order parameter i...

Apr 5, 2023
CVE-2023-25330
9.8

A SQL injection vulnerability in Mybatis Plus versions below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands by manipulating tenant ...

Apr 5, 2023
CVE-2020-20913
9.8

CVE-2020-20913 is a critical SQL injection vulnerability in Ming-Soft MCMS v4.7.2 that allows remote attackers to execute arbitrary SQL commands via t...

Apr 4, 2023
CVE-2020-20915
9.8

This is a critical SQL injection vulnerability in PublicCMS v4.0 that allows remote attackers to execute arbitrary SQL commands via the sql parameter ...

Apr 4, 2023
CVE-2023-26750
9.8

This SQL injection vulnerability in Yii Framework 2 allows remote attackers to execute arbitrary SQL commands through the runAction function, potentia...

Apr 4, 2023
CVE-2022-38922
9.8

BluePage CMS through version 3.9 has a SQL injection vulnerability in the 'users-cookie-settings' token due to insufficient sanitization of HTTP Cooki...

Apr 3, 2023
CVE-2023-1765
9.8

This SQL injection vulnerability in Akbim Computer Panon allows attackers to execute arbitrary SQL commands on the database. It affects all Panon inst...

Apr 3, 2023
CVE-2023-26858
9.8

This CVE describes a critical SQL injection vulnerability in the PrestaShop FAQs module v3.1.6, allowing remote attackers to execute arbitrary SQL com...

Mar 31, 2023
CVE-2022-36976
9.8

CVE-2022-36976 is a critical SQL injection vulnerability in Ivanti Avalanche that allows remote attackers to bypass authentication. The flaw exists in...

Mar 29, 2023
CVE-2022-36972
9.8

CVE-2022-36972 is a critical SQL injection vulnerability in Ivanti Avalanche that allows remote attackers to bypass authentication. The flaw exists in...

Mar 29, 2023
CVE-2023-27847
9.8

This SQL injection vulnerability in PrestaShop's xipblog module allows remote attackers to execute arbitrary SQL commands through the xipcategoryclass...

Mar 27, 2023
CVE-2023-26959
9.8

CVE-2023-26959 is a critical SQL injection vulnerability in Phpgurukul Park Ticketing Management System 1.0 that allows attackers to bypass authentica...

Mar 27, 2023
CVE-2023-28437
9.8

CVE-2023-28437 is a SQL injection vulnerability in Dataease open source data visualization tool caused by incomplete SQL injection blacklist protectio...

Mar 25, 2023
CVE-2023-26864
9.8

This SQL injection vulnerability in PrestaShop's smplredirectionsmanager module allows remote attackers to execute arbitrary SQL commands. Attackers c...

Mar 24, 2023
CVE-2023-28662
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Gift Cards plugin version 4.3.1 or ...

Mar 22, 2023
CVE-2023-27637
9.8

This CVE describes a SQL injection vulnerability in the tshirtecommerce (Custom Product Designer) component for PrestaShop. Attackers can forge HTTP r...

Mar 22, 2023
CVE-2023-27569
9.8

CVE-2023-27569 is a critical SQL injection vulnerability in the eo_tags module for PrestaShop that allows attackers to execute arbitrary SQL commands ...

Mar 21, 2023
CVE-2023-1153
9.8

This SQL injection vulnerability in Pacsrapor allows attackers to execute arbitrary SQL commands, potentially leading to command line execution. It af...

Mar 21, 2023
CVE-2023-26905
9.8

CVE-2023-26905 is a critical SQL injection vulnerability in Alphaware - Simple E-Commerce System v1.0 that allows attackers to execute arbitrary SQL c...

Mar 19, 2023
CVE-2023-27041
9.8

School Registration and Fee System v1.0 contains a SQL injection vulnerability in the id parameter at /bilal final/edit_user.php, allowing attackers t...

Mar 16, 2023
CVE-2023-27250
9.8

Online Book Store Project v1.0 contains a SQL injection vulnerability in the /bookstore/bookPerPub.php endpoint that allows attackers to execute arbit...

Mar 16, 2023
CVE-2023-24726
9.8

Art Gallery Management System v1.0 contains a SQL injection vulnerability in the viewid parameter on the enquiry page. This allows attackers to execut...

Mar 15, 2023
CVE-2023-27074
9.8

This vulnerability allows attackers to execute arbitrary SQL commands via the emailid parameter in the login page of BP Monitoring Management System v...

Mar 14, 2023
CVE-2023-25207
9.8

CVE-2023-25207 is a SQL injection vulnerability in the DPD France module for PrestaShop that allows attackers to execute arbitrary SQL commands via th...

Mar 13, 2023
CVE-2023-1198
9.8

This SQL injection vulnerability in Saysis Starcities allows attackers to execute arbitrary SQL commands through the application. It affects all Starc...

Mar 10, 2023

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,699 CVEs classified as CWE-89, with 2,059 rated critical and 1,989 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free