CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,717
Total CVEs
2,067
Critical
1,999
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
242
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 130
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,717)

CVE-2022-3915
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Dokan plugin. Attackers can potenti...

Dec 12, 2022
CVE-2022-44151
9.8

CVE-2022-44151 is a critical SQL injection vulnerability in Simple Inventory Management System v1.0's login.php endpoint that allows attackers to exec...

Nov 30, 2022
CVE-2022-22280
9.8

This is an unauthenticated SQL injection vulnerability in SonicWall GMS and Analytics On-Prem products. Attackers can execute arbitrary SQL commands w...

Jul 29, 2022
CVE-2022-34989
9.8

Fruits Bazar v1.0 contains a SQL injection vulnerability in the password recovery function via the recover_email parameter. This allows attackers to e...

Jul 26, 2022
CVE-2022-36161
9.8

Orange Station 1.0 contains a SQL injection vulnerability in the username parameter that allows attackers to execute arbitrary SQL commands. This affe...

Jul 26, 2022
CVE-2022-32456
9.8

This is a critical SQL injection vulnerability in Digiwin BPM software that allows unauthenticated remote attackers to execute arbitrary SQL commands....

Jul 20, 2022
CVE-2022-34023
9.8

Barangay Management System v1.0 contains a SQL injection vulnerability in the hidden_id parameter at /officials/officials.php. This allows attackers t...

Jul 19, 2022
CVE-2022-27434
9.8

CVE-2022-27434 is a SQL injection vulnerability in UNIT4 TETA Mobile Edition that allows attackers to execute arbitrary SQL commands via the ProfileNa...

Jul 18, 2022
CVE-2022-30113
9.8

Electronic Mall System 1.0_build20200203 contains a SQL injection vulnerability (CWE-89) that allows attackers to execute arbitrary SQL commands throu...

Jul 14, 2022
CVE-2022-35628
9.8

This CVE describes a SQL injection vulnerability in the lux extension for TYPO3 CMS. Attackers can execute arbitrary SQL commands through the extensio...

Jul 12, 2022
CVE-2022-29600
9.8

CVE-2022-29600 is a SQL injection vulnerability in the oelib extension for TYPO3 CMS. It allows attackers to execute arbitrary SQL commands through cr...

Jul 12, 2022
CVE-2022-1057
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WooCommerce websites using the Pricing Deals plugin. Attacker...

Jul 11, 2022
CVE-2022-28623
9.8

This vulnerability allows remote attackers to execute SQL injection attacks against HPE IceWall SSO 10.0 certd component, potentially leading to unaut...

Jul 8, 2022
CVE-2022-32056
9.8

Online Accreditation Management System v1.0 contains a SQL injection vulnerability in the USERNAME parameter at process.php. This allows attackers to ...

Jul 7, 2022
CVE-2022-31056
9.8

CVE-2022-31056 is a critical SQL injection vulnerability in GLPI's assistance forms (Ticket/Change/Problem) that allows attackers to execute arbitrary...

Jun 28, 2022
CVE-2022-34132
9.8

CVE-2022-34132 is a SQL injection vulnerability in Benjamin BALET Jorani v1.0 that allows attackers to execute arbitrary SQL commands via the id param...

Jun 28, 2022
CVE-2022-31361
9.8

CVE-2022-31361 is a SQL injection vulnerability in Docebo Community Edition v4.0.5 and below that allows attackers to execute arbitrary SQL commands. ...

Jun 23, 2022
CVE-2022-31787
9.8

CVE-2022-31787 is a critical SQL injection vulnerability in IdeaTMS 2022 that allows attackers to execute arbitrary SQL commands via the PATH_INFO par...

Jun 23, 2022
CVE-2022-1905
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Events Made Easy plugin. Attackers ...

Jun 20, 2022
CVE-2022-31941
9.8

CVE-2022-31941 is a critical SQL injection vulnerability in Rescue Dispatch Management System v1.0 that allows attackers to execute arbitrary SQL comm...

Jun 17, 2022
CVE-2022-31355
9.8

Online Ordering System v2.3.2 contains a SQL injection vulnerability in the category search parameter. Attackers can execute arbitrary SQL commands th...

Jun 17, 2022
CVE-2022-31357
9.8

Online Ordering System v2.3.2 contains a SQL injection vulnerability in the inventory management interface that allows attackers to execute arbitrary ...

Jun 17, 2022
CVE-2022-31296
9.8

CVE-2022-31296 is a blind SQL injection vulnerability in Online Discussion Forum Site 1's view_post.php component that allows attackers to execute arb...

Jun 17, 2022
CVE-2021-41408
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the VoIPmonitor WEB GUI's api.php file via the 'user' parameter. It affe...

Jun 17, 2022
CVE-2021-41487
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the UserName parameter in NOKIA VitalSuite SPM 2020. Successful exploita...

Jun 16, 2022
CVE-2022-31382
9.8

Directory Management System v1.0 contains a SQL injection vulnerability in the search-dirctory.php file via the searchdata parameter. This allows atta...

Jun 16, 2022
CVE-2022-31384
9.8

Directory Management System v1.0 contains a SQL injection vulnerability in the fullname parameter of add-directory.php. This allows attackers to execu...

Jun 16, 2022
CVE-2022-32301
9.8

CVE-2022-32301 is a critical SQL injection vulnerability in YoudianCMS v9.5.0 that allows attackers to execute arbitrary SQL commands via the IdList p...

Jun 15, 2022
CVE-2022-32101
9.8

CVE-2022-32101 is a SQL injection vulnerability in kkcms v1.3.7 that allows attackers to execute arbitrary SQL commands via the cid parameter in /temp...

Jun 15, 2022
CVE-2019-4575
9.8

This SQL injection vulnerability in IBM Financial Transaction Manager for Digital Payments allows remote attackers to execute arbitrary SQL commands. ...

Jun 15, 2022
CVE-2022-32336
9.8

Fast Food Ordering System v1.0 contains a SQL injection vulnerability in the admin menu viewing functionality. Attackers can exploit this by manipulat...

Jun 14, 2022
CVE-2021-41661
9.8

Church Management System version 1.0 has a critical SQL injection vulnerability that allows attackers to upload PHP files disguised as avatar images. ...

Jun 13, 2022
CVE-2022-0786
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the KiviCare plugin. It affects all Wor...

Jun 13, 2022
CVE-2021-41756
9.8

CVE-2021-41756 is a SQL injection vulnerability in dynamicMarkt marketplace software that allows attackers to execute arbitrary SQL commands through t...

Jun 10, 2022
CVE-2021-41754
9.8

CVE-2021-41754 is a SQL injection vulnerability in dynamicMarkt software that allows attackers to execute arbitrary SQL commands through the parent pa...

Jun 10, 2022
CVE-2022-31788
9.8

This vulnerability allows attackers to execute arbitrary SQL commands via the ClassID parameter in IdeaLMS 2022's chat room access control endpoint. I...

Jun 10, 2022
CVE-2022-30927
9.8

Simple Task Scheduling System 1.0 contains an unauthenticated SQL injection vulnerability in the 'id' parameter when using MySQL. Attackers can execut...

Jun 6, 2022
CVE-2022-31768
9.8

This SQL injection vulnerability in IBM InfoSphere Information Server 11.7 allows remote attackers to execute arbitrary SQL commands against the back-...

Jun 6, 2022
CVE-2022-29704
9.8

BrowsBox CMS v4.0 contains a SQL injection vulnerability that allows attackers to execute arbitrary SQL commands through user input. This affects all ...

Jun 2, 2022
CVE-2022-31989
9.8

Badminton Center Management System v1.0 contains a SQL injection vulnerability in the admin panel's user management page. Attackers can exploit this t...

Jun 2, 2022
CVE-2022-31991
9.8

Badminton Center Management System v1.0 contains a SQL injection vulnerability in the delete_court function that allows attackers to execute arbitrary...

Jun 2, 2022
CVE-2022-31993
9.8

Badminton Center Management System v1.0 contains a SQL injection vulnerability in the delete_service function that allows attackers to execute arbitra...

Jun 2, 2022
CVE-2022-32002
9.8

Badminton Center Management System v1.0 contains a SQL injection vulnerability in the admin panel's court management module. Attackers can exploit thi...

Jun 2, 2022
CVE-2022-31951
9.8

Rescue Dispatch Management System v1.0 contains a SQL injection vulnerability in the delete_respondent_type function that allows attackers to execute ...

Jun 2, 2022
CVE-2022-31953
9.8

Rescue Dispatch Management System v1.0 contains a SQL injection vulnerability in the incident report viewer that allows attackers to execute arbitrary...

Jun 2, 2022
CVE-2022-31957
9.8

Rescue Dispatch Management System v1.0 contains a SQL injection vulnerability in the admin teams view page that allows attackers to execute arbitrary ...

Jun 2, 2022
CVE-2022-31961
9.8

CVE-2022-31961 is a critical SQL injection vulnerability in Rescue Dispatch Management System v1.0 that allows attackers to execute arbitrary SQL comm...

Jun 2, 2022
CVE-2022-31964
9.8

CVE-2022-31964 is a critical SQL injection vulnerability in Rescue Dispatch Management System v1.0 that allows attackers to execute arbitrary SQL comm...

Jun 2, 2022
CVE-2022-31969
9.8

ChatBot App with Suggestion v1.0 contains a SQL injection vulnerability in the user management admin panel. Attackers can exploit this by manipulating...

Jun 2, 2022
CVE-2022-31976
9.8

Online Fire Reporting System v1.0 contains a SQL injection vulnerability in the delete_request function that allows attackers to execute arbitrary SQL...

Jun 2, 2022

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,717 CVEs classified as CWE-89, with 2,067 rated critical and 1,999 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free