CWE-89: SQL Injection
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Yearly Trend
Top Affected Vendors
All SQL Injection CVEs (4,717)
This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Dokan plugin. Attackers can potenti...
Dec 12, 2022CVE-2022-44151 is a critical SQL injection vulnerability in Simple Inventory Management System v1.0's login.php endpoint that allows attackers to exec...
Nov 30, 2022This is an unauthenticated SQL injection vulnerability in SonicWall GMS and Analytics On-Prem products. Attackers can execute arbitrary SQL commands w...
Jul 29, 2022Fruits Bazar v1.0 contains a SQL injection vulnerability in the password recovery function via the recover_email parameter. This allows attackers to e...
Jul 26, 2022Orange Station 1.0 contains a SQL injection vulnerability in the username parameter that allows attackers to execute arbitrary SQL commands. This affe...
Jul 26, 2022This is a critical SQL injection vulnerability in Digiwin BPM software that allows unauthenticated remote attackers to execute arbitrary SQL commands....
Jul 20, 2022Barangay Management System v1.0 contains a SQL injection vulnerability in the hidden_id parameter at /officials/officials.php. This allows attackers t...
Jul 19, 2022CVE-2022-27434 is a SQL injection vulnerability in UNIT4 TETA Mobile Edition that allows attackers to execute arbitrary SQL commands via the ProfileNa...
Jul 18, 2022Electronic Mall System 1.0_build20200203 contains a SQL injection vulnerability (CWE-89) that allows attackers to execute arbitrary SQL commands throu...
Jul 14, 2022This CVE describes a SQL injection vulnerability in the lux extension for TYPO3 CMS. Attackers can execute arbitrary SQL commands through the extensio...
Jul 12, 2022CVE-2022-29600 is a SQL injection vulnerability in the oelib extension for TYPO3 CMS. It allows attackers to execute arbitrary SQL commands through cr...
Jul 12, 2022This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WooCommerce websites using the Pricing Deals plugin. Attacker...
Jul 11, 2022This vulnerability allows remote attackers to execute SQL injection attacks against HPE IceWall SSO 10.0 certd component, potentially leading to unaut...
Jul 8, 2022Online Accreditation Management System v1.0 contains a SQL injection vulnerability in the USERNAME parameter at process.php. This allows attackers to ...
Jul 7, 2022CVE-2022-31056 is a critical SQL injection vulnerability in GLPI's assistance forms (Ticket/Change/Problem) that allows attackers to execute arbitrary...
Jun 28, 2022CVE-2022-34132 is a SQL injection vulnerability in Benjamin BALET Jorani v1.0 that allows attackers to execute arbitrary SQL commands via the id param...
Jun 28, 2022CVE-2022-31361 is a SQL injection vulnerability in Docebo Community Edition v4.0.5 and below that allows attackers to execute arbitrary SQL commands. ...
Jun 23, 2022CVE-2022-31787 is a critical SQL injection vulnerability in IdeaTMS 2022 that allows attackers to execute arbitrary SQL commands via the PATH_INFO par...
Jun 23, 2022This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Events Made Easy plugin. Attackers ...
Jun 20, 2022CVE-2022-31941 is a critical SQL injection vulnerability in Rescue Dispatch Management System v1.0 that allows attackers to execute arbitrary SQL comm...
Jun 17, 2022Online Ordering System v2.3.2 contains a SQL injection vulnerability in the category search parameter. Attackers can execute arbitrary SQL commands th...
Jun 17, 2022Online Ordering System v2.3.2 contains a SQL injection vulnerability in the inventory management interface that allows attackers to execute arbitrary ...
Jun 17, 2022CVE-2022-31296 is a blind SQL injection vulnerability in Online Discussion Forum Site 1's view_post.php component that allows attackers to execute arb...
Jun 17, 2022This vulnerability allows attackers to execute arbitrary SQL commands through the VoIPmonitor WEB GUI's api.php file via the 'user' parameter. It affe...
Jun 17, 2022This vulnerability allows attackers to execute arbitrary SQL commands through the UserName parameter in NOKIA VitalSuite SPM 2020. Successful exploita...
Jun 16, 2022Directory Management System v1.0 contains a SQL injection vulnerability in the search-dirctory.php file via the searchdata parameter. This allows atta...
Jun 16, 2022Directory Management System v1.0 contains a SQL injection vulnerability in the fullname parameter of add-directory.php. This allows attackers to execu...
Jun 16, 2022CVE-2022-32301 is a critical SQL injection vulnerability in YoudianCMS v9.5.0 that allows attackers to execute arbitrary SQL commands via the IdList p...
Jun 15, 2022CVE-2022-32101 is a SQL injection vulnerability in kkcms v1.3.7 that allows attackers to execute arbitrary SQL commands via the cid parameter in /temp...
Jun 15, 2022This SQL injection vulnerability in IBM Financial Transaction Manager for Digital Payments allows remote attackers to execute arbitrary SQL commands. ...
Jun 15, 2022Fast Food Ordering System v1.0 contains a SQL injection vulnerability in the admin menu viewing functionality. Attackers can exploit this by manipulat...
Jun 14, 2022Church Management System version 1.0 has a critical SQL injection vulnerability that allows attackers to upload PHP files disguised as avatar images. ...
Jun 13, 2022This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the KiviCare plugin. It affects all Wor...
Jun 13, 2022CVE-2021-41756 is a SQL injection vulnerability in dynamicMarkt marketplace software that allows attackers to execute arbitrary SQL commands through t...
Jun 10, 2022CVE-2021-41754 is a SQL injection vulnerability in dynamicMarkt software that allows attackers to execute arbitrary SQL commands through the parent pa...
Jun 10, 2022This vulnerability allows attackers to execute arbitrary SQL commands via the ClassID parameter in IdeaLMS 2022's chat room access control endpoint. I...
Jun 10, 2022Simple Task Scheduling System 1.0 contains an unauthenticated SQL injection vulnerability in the 'id' parameter when using MySQL. Attackers can execut...
Jun 6, 2022This SQL injection vulnerability in IBM InfoSphere Information Server 11.7 allows remote attackers to execute arbitrary SQL commands against the back-...
Jun 6, 2022BrowsBox CMS v4.0 contains a SQL injection vulnerability that allows attackers to execute arbitrary SQL commands through user input. This affects all ...
Jun 2, 2022Badminton Center Management System v1.0 contains a SQL injection vulnerability in the admin panel's user management page. Attackers can exploit this t...
Jun 2, 2022Badminton Center Management System v1.0 contains a SQL injection vulnerability in the delete_court function that allows attackers to execute arbitrary...
Jun 2, 2022Badminton Center Management System v1.0 contains a SQL injection vulnerability in the delete_service function that allows attackers to execute arbitra...
Jun 2, 2022Badminton Center Management System v1.0 contains a SQL injection vulnerability in the admin panel's court management module. Attackers can exploit thi...
Jun 2, 2022Rescue Dispatch Management System v1.0 contains a SQL injection vulnerability in the delete_respondent_type function that allows attackers to execute ...
Jun 2, 2022Rescue Dispatch Management System v1.0 contains a SQL injection vulnerability in the incident report viewer that allows attackers to execute arbitrary...
Jun 2, 2022Rescue Dispatch Management System v1.0 contains a SQL injection vulnerability in the admin teams view page that allows attackers to execute arbitrary ...
Jun 2, 2022CVE-2022-31961 is a critical SQL injection vulnerability in Rescue Dispatch Management System v1.0 that allows attackers to execute arbitrary SQL comm...
Jun 2, 2022CVE-2022-31964 is a critical SQL injection vulnerability in Rescue Dispatch Management System v1.0 that allows attackers to execute arbitrary SQL comm...
Jun 2, 2022ChatBot App with Suggestion v1.0 contains a SQL injection vulnerability in the user management admin panel. Attackers can exploit this by manipulating...
Jun 2, 2022Online Fire Reporting System v1.0 contains a SQL injection vulnerability in the delete_request function that allows attackers to execute arbitrary SQL...
Jun 2, 2022About SQL Injection (CWE-89)
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Our database tracks 4,717 CVEs classified as CWE-89, with 2,067 rated critical and 1,999 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.
External reference: View CWE-89 on MITRE CWE →
Monitor SQL Injection Vulnerabilities
Get alerted when new SQL Injection CVEs affect your infrastructure.
Start Monitoring Free