CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,717
Total CVEs
2,067
Critical
1,999
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
242
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 130
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,717)

CVE-2023-24774
9.8

Funadmin v3.2.0 contains a SQL injection vulnerability in the selectFields parameter at controller/auth/Auth.php. This allows attackers to execute arb...

Mar 10, 2023
CVE-2023-1091
9.8

This SQL injection vulnerability in Alpata Licensed Warehousing Automation System allows attackers to execute arbitrary SQL commands, potentially lead...

Mar 10, 2023
CVE-2023-27203
9.8

Best POS Management System 1.0 contains a SQL injection vulnerability in the id parameter at /billing/home.php. This allows attackers to execute arbit...

Mar 9, 2023
CVE-2023-27205
9.8

CVE-2023-27205 is a critical SQL injection vulnerability in Best POS Management System 1.0 that allows attackers to execute arbitrary SQL commands via...

Mar 9, 2023
CVE-2023-27207
9.8

Online Pizza Ordering System 1.0 contains a SQL injection vulnerability in the admin/manage_user.php endpoint via the id parameter. This allows attack...

Mar 9, 2023
CVE-2023-27210
9.8

This CVE describes a SQL injection vulnerability in Online Pizza Ordering System 1.0, allowing attackers to execute arbitrary SQL commands via the 'id...

Mar 9, 2023
CVE-2023-27213
9.8

This SQL injection vulnerability in Online Student Management System v1.0 allows attackers to execute arbitrary SQL commands via the searchdata parame...

Mar 9, 2023
CVE-2023-1251
9.8

This SQL injection vulnerability in Akinsoft Wolvox allows attackers to execute arbitrary SQL commands on the database. It affects all Wolvox installa...

Mar 9, 2023
CVE-2023-24777
9.8

Funadmin v3.2.0 contains a SQL injection vulnerability in the id parameter at /databases/table/list endpoint. This allows attackers to execute arbitra...

Mar 8, 2023
CVE-2023-24782
9.8

Funadmin v3.2.0 contains a SQL injection vulnerability in the id parameter at /databases/database/edit endpoint. This allows attackers to execute arbi...

Mar 8, 2023
CVE-2023-26922
9.8

CVE-2023-26922 is a critical SQL injection vulnerability in Varisicte matrix-gui v.2 that allows remote attackers to execute arbitrary code via the sh...

Mar 8, 2023
CVE-2023-1267
9.8

This SQL injection vulnerability in Ulkem Company's PtteM Kart software allows attackers to execute arbitrary SQL commands on the database. It affects...

Mar 8, 2023
CVE-2023-24780
9.8

Funadmin v3.2.0 contains a SQL injection vulnerability in the id parameter at /databases/table/columns endpoint. This allows attackers to execute arbi...

Mar 8, 2023
CVE-2023-24775
9.8

Funadmin v3.2.0 contains a SQL injection vulnerability in the selectFields parameter at /member/Member.php that allows attackers to execute arbitrary ...

Mar 7, 2023
CVE-2023-24781
9.8

Funadmin v3.2.0 contains a SQL injection vulnerability in the selectFields parameter at /member/MemberLevel.php. This allows attackers to execute arbi...

Mar 7, 2023
CVE-2022-3760
9.8

This SQL injection vulnerability in Mia Technology's Mia-Med software allows attackers to execute arbitrary SQL commands by injecting malicious input....

Mar 7, 2023
CVE-2021-36392
9.8

CVE-2021-36392 is a critical SQL injection vulnerability in Moodle's user enrollment library that allows attackers to execute arbitrary SQL queries. T...

Mar 6, 2023
CVE-2023-0979
9.8

This SQL injection vulnerability in MedDataPACS allows attackers to execute arbitrary SQL commands on the database. It affects all MedDataPACS install...

Mar 6, 2023
CVE-2023-24641
9.8

Judging Management System v1.0 contains a SQL injection vulnerability in the sid parameter at /php-jms/updateview.php that allows attackers to execute...

Mar 3, 2023
CVE-2023-24643
9.8

This SQL injection vulnerability in Judging Management System v1.0 allows attackers to execute arbitrary SQL commands via the sid parameter in the upd...

Mar 3, 2023
CVE-2022-46501
9.8

This SQL injection vulnerability in Accruent Maintenance Connection allows attackers to execute arbitrary SQL commands through the E-Mail to Work Orde...

Mar 2, 2023
CVE-2023-26780
9.8

CVE-2023-26780 is a SQL injection vulnerability in CleverStupidDog yf-exam version 1.8.0 that allows attackers to execute arbitrary SQL commands. This...

Mar 2, 2023
CVE-2021-3854
9.8

This SQL injection vulnerability in Glox Technology Useroam Hotspot allows attackers to execute arbitrary SQL commands through unvalidated user input....

Mar 2, 2023
CVE-2023-23315
9.8

CVE-2023-23315 is a critical blind SQL injection vulnerability in the PrestaShop stripejs module that allows attackers to execute arbitrary SQL comman...

Mar 1, 2023
CVE-2023-1064
9.8

This SQL injection vulnerability in Uzay Baskul Weighbridge Automation Software allows attackers to execute arbitrary SQL commands on the database. It...

Mar 1, 2023
CVE-2023-24253
9.8

This SQL injection vulnerability in Domotica Labs srl Ikon Server allows attackers to execute arbitrary SQL commands on the database. It affects all I...

Feb 27, 2023
CVE-2023-23155
9.8

This SQL injection vulnerability in Art Gallery Management System 1.0 allows attackers to execute arbitrary SQL commands via the username parameter in...

Feb 27, 2023
CVE-2023-24206
9.8

Davinci v0.3.0-rc contains a SQL injection vulnerability in the copyDisplay function that allows attackers to execute arbitrary SQL commands. This aff...

Feb 27, 2023
CVE-2023-26550
9.8

This SQL injection vulnerability in BMC Control-M allows attackers to execute arbitrary SQL commands via the memname JSON field. Attackers could poten...

Feb 25, 2023
CVE-2022-2504
9.8

This SQL injection vulnerability in SDD-Baro software allows attackers to execute arbitrary SQL commands on the database. It affects all SDD-Baro vers...

Feb 23, 2023
CVE-2023-0939
9.8

This SQL injection vulnerability in NTN Information Technologies Online Services Software allows attackers to execute arbitrary SQL commands by inject...

Feb 23, 2023
CVE-2022-48149
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the username parameter in Online Student Admission System 1.0. Attackers...

Feb 22, 2023
CVE-2022-45564
9.8

This CVE describes a SQL injection vulnerability in znfit Home improvement ERP management system that allows attackers to execute arbitrary SQL comman...

Feb 21, 2023
CVE-2023-23279
9.8

CVE-2023-23279 is a critical SQL injection vulnerability in Canteen Management System 1.0 that allows attackers to execute arbitrary SQL commands via ...

Feb 17, 2023
CVE-2021-33948
9.8

This SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attackers to execute arbitrary SQL commands via the username parameter. Att...

Feb 17, 2023
CVE-2022-40032
9.8

CVE-2022-40032 is a critical SQL injection vulnerability in Simple Task Managing System version 1.0 that allows unauthenticated attackers to execute a...

Feb 17, 2023
CVE-2022-40347
9.8

This CVE describes an unauthenticated SQL injection vulnerability in Intern Record System version 1.0. Attackers can exploit parameters in the control...

Feb 17, 2023
CVE-2023-24221
9.8

LuckyframeWEB v3.5 contains a SQL injection vulnerability in the dataScope parameter at /system/DeptMapper.xml that allows attackers to execute arbitr...

Feb 17, 2023
CVE-2023-24219
9.8

LuckyframeWEB v3.5 contains a SQL injection vulnerability in the dataScope parameter at /system/UserMapper.xml that allows attackers to execute arbitr...

Feb 17, 2023
CVE-2021-33925
9.8

This CVE describes an SQL injection vulnerability in the cms-corephp project that allows unauthenticated attackers to bypass authentication and gain e...

Feb 15, 2023
CVE-2020-21119
9.8

This SQL injection vulnerability in Kliqqi-CMS allows attackers to manipulate database queries through the recordIDValue parameter in the admin panel....

Feb 15, 2023
CVE-2023-24084
9.8

CVE-2023-24084 is a critical SQL injection vulnerability in ChiKoi v1.0 that allows attackers to execute arbitrary SQL commands via the load_file func...

Feb 13, 2023
CVE-2022-4557
9.8

This SQL injection vulnerability in Group Arge Energy and Control Systems Smartpower Web allows attackers to execute arbitrary SQL commands through th...

Feb 12, 2023
CVE-2023-23162
9.8

This SQL injection vulnerability in Art Gallery Management System v1.0 allows attackers to execute arbitrary SQL commands via the cid parameter in pro...

Feb 10, 2023
CVE-2022-45526
9.8

This SQL injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0 allows attackers to execute arbitrary SQL commands via the...

Feb 8, 2023
CVE-2023-24200
9.8

Raffle Draw System v1.0 contains a SQL injection vulnerability in the save_ticket.php file via the id parameter. This allows attackers to execute arbi...

Feb 6, 2023
CVE-2023-24198
9.8

Raffle Draw System v1.0 contains SQL injection vulnerabilities in the save_winner.php endpoint via ticket_id and draw parameters. This allows attacker...

Feb 6, 2023
CVE-2021-37497
9.8

CVE-2021-37497 is a critical SQL injection vulnerability in PbootCMS 3.0.5 that allows remote attackers to execute arbitrary SQL commands via crafted ...

Feb 3, 2023
CVE-2021-36484
9.8

This SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to execute arbitrary SQL commands through the add or edit article pages. Attackers...

Feb 3, 2023
CVE-2021-36503
9.8

This SQL injection vulnerability in native-php-cms 1.0 allows remote attackers to execute arbitrary SQL commands through the cat parameter in /list.ph...

Feb 3, 2023

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,717 CVEs classified as CWE-89, with 2,067 rated critical and 1,999 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free