CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,717
Total CVEs
2,067
Critical
1,999
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
242
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 130
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,717)

CVE-2022-31978
9.8

Online Fire Reporting System v1.0 contains a SQL injection vulnerability in the delete_inquiry function that allows attackers to execute arbitrary SQL...

Jun 2, 2022
CVE-2022-31946
9.8

CVE-2022-31946 is a critical SQL injection vulnerability in Rescue Dispatch Management System v1.0 that allows attackers to execute arbitrary SQL comm...

Jun 2, 2022
CVE-2022-31340
9.8

Simple Inventory System v1.0 contains a SQL injection vulnerability in the table_edit_ajax.php endpoint that allows attackers to execute arbitrary SQL...

Jun 2, 2022
CVE-2022-31343
9.8

Online Car Wash Booking System v1.0 contains a SQL injection vulnerability in the admin booking details page that allows attackers to execute arbitrar...

Jun 2, 2022
CVE-2022-31345
9.8

Online Car Wash Booking System v1.0 contains a SQL injection vulnerability in the admin panel's user management page. Attackers can exploit this to ex...

Jun 2, 2022
CVE-2022-31347
9.8

Online Car Wash Booking System v1.0 contains a SQL injection vulnerability in the delete_vehicle function that allows attackers to execute arbitrary S...

Jun 2, 2022
CVE-2022-31350
9.8

Online Car Wash Booking System v1.0 contains a SQL injection vulnerability in the admin vehicle management interface that allows attackers to execute ...

Jun 2, 2022
CVE-2022-31352
9.8

CVE-2022-31352 is a critical SQL injection vulnerability in Online Car Wash Booking System v1.0 that allows attackers to execute arbitrary SQL command...

Jun 2, 2022
CVE-2022-31354
9.8

Online Car Wash Booking System v1.0 contains a SQL injection vulnerability in the get_vehicle_service endpoint that allows attackers to execute arbitr...

Jun 2, 2022
CVE-2022-31327
9.8

Online Ordering System version 2.3.2 contains a SQL injection vulnerability in the products parameter that allows attackers to execute arbitrary SQL c...

Jun 2, 2022
CVE-2022-31329
9.8

CVE-2022-31329 is a critical SQL injection vulnerability in Online Ordering System by janobe version 2.3.2 that allows attackers to execute arbitrary ...

Jun 2, 2022
CVE-2022-31336
9.8

Online Ordering System 2.3.2 contains a SQL injection vulnerability in the /ordering/admin/stockin/loaddata.php endpoint that allows attackers to exec...

Jun 2, 2022
CVE-2022-31338
9.8

Online Ordering System 2.3.2 contains a SQL injection vulnerability in the admin user management interface that allows attackers to execute arbitrary ...

Jun 2, 2022
CVE-2022-30810
9.8

EliteCMS v1.01 contains a SQL injection vulnerability in the admin/edit_post.php endpoint that allows attackers to execute arbitrary SQL commands. Thi...

Jun 2, 2022
CVE-2022-30814
9.8

EliteCMS v1.01 contains a SQL injection vulnerability in the /admin/add_sidebar.php endpoint that allows attackers to execute arbitrary SQL commands. ...

Jun 2, 2022
CVE-2022-30816
9.8

CVE-2022-30816 is a critical SQL injection vulnerability in elitecms 1.01 that allows attackers to execute arbitrary SQL commands via the /admin/edit_...

Jun 2, 2022
CVE-2022-30797
9.8

Online Ordering System 1.0 contains a SQL injection vulnerability in the admin/vieworders.php endpoint that allows attackers to execute arbitrary SQL ...

Jun 2, 2022
CVE-2022-30511
9.8

CVE-2022-30511 is a critical SQL injection vulnerability in School Dormitory Management System 1.0 that allows attackers to execute arbitrary SQL comm...

Jun 2, 2022
CVE-2022-30481
9.8

CVE-2022-30481 is a critical SQL injection vulnerability in Food Order and Table Reservation System 1.0 that allows attackers to execute arbitrary SQL...

Jun 2, 2022
CVE-2022-30490
9.8

Badminton Center Management System V1.0 contains an SQL injection vulnerability in the court rental status update functionality. Attackers can exploit...

Jun 2, 2022
CVE-2022-30352
9.8

CVE-2022-30352 is a SQL injection vulnerability in phpABook 0.9i that allows attackers to execute arbitrary SQL commands via the 'auth_user' parameter...

Jun 2, 2022
CVE-2022-29659
9.8

This vulnerability allows attackers to execute arbitrary SQL commands via the 'id' parameter in single.php in Responsive Online Blog v1.0. This can le...

Jun 2, 2022
CVE-2021-44095
9.8

CVE-2021-44095 is a critical SQL injection vulnerability in ProjectWorlds Hospital Management System in PHP 1.0 that allows remote attackers to execut...

Jun 2, 2022
CVE-2021-44097
9.8

CVE-2021-44097 is a critical SQL injection vulnerability in EGavilan Media's Contact-Form-With-Messages-Entry-Management plugin version 1.0. Attackers...

Jun 2, 2022
CVE-2021-26634
9.8

CVE-2021-26634 is a critical vulnerability in Maxboard software that allows SQL injection and file upload attacks due to insufficient input validation...

Jun 2, 2022
CVE-2019-12349
9.8

This SQL injection vulnerability in zzcms 2019 allows attackers to execute arbitrary SQL commands through the id parameter in /admin/dl_sendsms.php. T...

Jun 2, 2022
CVE-2019-12351
9.8

This SQL injection vulnerability in zzcms 2019 allows attackers to execute arbitrary SQL commands via the id parameter in dl/dl_print.php. Any system ...

Jun 2, 2022
CVE-2022-1556
9.8

This vulnerability allows attackers to execute arbitrary SQL commands on WordPress sites using the StaffList plugin before version 3.1.5. The SQL inje...

May 30, 2022
CVE-2022-30493
9.8

CVE-2022-30493 is a critical SQL injection vulnerability in oretnom23 Automotive Shop Management System v1.0 that allows remote attackers to extract d...

May 26, 2022
CVE-2022-30500
9.8

CVE-2022-30500 is a SQL injection vulnerability in Jfinal CMS 5.1.0 that allows attackers to execute arbitrary SQL commands through crafted inputs. Th...

May 26, 2022
CVE-2022-29660
9.8

CVE-2022-29660 is a critical SQL injection vulnerability in CSCMS Music Portal System v4.2 that allows attackers to execute arbitrary SQL commands via...

May 26, 2022
CVE-2022-30838
9.8

CVE-2022-30838 is a critical SQL injection vulnerability in Covid-19 Travel Pass Management System v1.0 that allows attackers to execute arbitrary SQL...

May 24, 2022
CVE-2022-30461
9.8

Water Billing Management System v1.0 contains a SQL injection vulnerability in the delete_client function that allows attackers to execute arbitrary S...

May 24, 2022
CVE-2022-30454
9.8

Merchandise Online Store 1.0 contains a SQL injection vulnerability in the delete_product function that allows attackers to execute arbitrary SQL comm...

May 24, 2022
CVE-2022-0781
9.8

CVE-2022-0781 is an unauthenticated SQL injection vulnerability in the Nirweb Support WordPress plugin. Attackers can execute arbitrary SQL commands t...

May 23, 2022
CVE-2022-28531
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the username field in the admin login page of Covid-19 Directory on Vacc...

May 20, 2022
CVE-2022-30518
9.8

This CVE describes a SQL injection vulnerability in ChatBot Application with a Suggestion Feature 1.0. Attackers can inject malicious SQL commands via...

May 20, 2022
CVE-2021-37413
9.8

CVE-2021-37413 is a critical SQL injection vulnerability in GRANDCOM DynWEB's admin login interface that allows unauthenticated attackers to execute a...

May 19, 2022
CVE-2022-30599
9.8

CVE-2022-30599 is a critical SQL injection vulnerability in Moodle's badges functionality that allows attackers to execute arbitrary SQL commands. Thi...

May 18, 2022
CVE-2022-30052
9.8

CVE-2022-30052 is a critical SQL injection vulnerability in Home Clean Service System 1.0's password parameter, allowing attackers to execute arbitrar...

May 17, 2022
CVE-2022-30054
9.8

CVE-2022-30054 is a critical SQL injection vulnerability in Covid 19 Travel Pass Management 1.0 that allows attackers to execute arbitrary SQL command...

May 17, 2022
CVE-2022-1731
9.8

Metasonic Doc WebClient versions 7.0.14.0, 7.0.12.0, and 7.0.3.0 contain a SQL injection vulnerability in the username field when SSO or System authen...

May 16, 2022
CVE-2022-0867
9.8

CVE-2022-0867 is a critical SQL injection vulnerability in the Pricing Table WordPress plugin that allows unauthenticated attackers to execute arbitra...

May 16, 2022
CVE-2022-30011
9.8

CVE-2022-30011 is a critical SQL injection vulnerability in HMS 1.0's appointment.php endpoint that allows attackers to execute arbitrary SQL commands...

May 16, 2022
CVE-2022-30765
9.8

CVE-2022-30765 is a SQL injection vulnerability in Calibre-Web's user table functionality that allows attackers to execute arbitrary SQL commands. Thi...

May 16, 2022
CVE-2022-28930
9.8

ERP-Pro v3.7.5 contains a SQL injection vulnerability in the SysEveMenuAuthPointMapper.xml component that allows attackers to execute arbitrary SQL co...

May 15, 2022
CVE-2022-28929
9.8

Hospital Management System v1.0 contains a SQL injection vulnerability in the delid parameter at viewtreatmentrecord.php that allows attackers to exec...

May 15, 2022
CVE-2022-30413
9.8

CVE-2022-30413 is a critical SQL injection vulnerability in Covid-19 Travel Pass Management System v1.0 that allows attackers to execute arbitrary SQL...

May 13, 2022
CVE-2022-30384
9.8

Merchandise Online Store v1.0 contains a SQL injection vulnerability in the delete_inventory function that allows attackers to execute arbitrary SQL c...

May 13, 2022
CVE-2022-30386
9.8

Merchandise Online Store v1.0 contains a SQL injection vulnerability in the delete_featured function that allows attackers to execute arbitrary SQL co...

May 13, 2022

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,717 CVEs classified as CWE-89, with 2,067 rated critical and 1,999 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free