CWE-89: SQL Injection
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Yearly Trend
Top Affected Vendors
All SQL Injection CVEs (4,717)
Online Fire Reporting System v1.0 contains a SQL injection vulnerability in the delete_inquiry function that allows attackers to execute arbitrary SQL...
Jun 2, 2022CVE-2022-31946 is a critical SQL injection vulnerability in Rescue Dispatch Management System v1.0 that allows attackers to execute arbitrary SQL comm...
Jun 2, 2022Simple Inventory System v1.0 contains a SQL injection vulnerability in the table_edit_ajax.php endpoint that allows attackers to execute arbitrary SQL...
Jun 2, 2022Online Car Wash Booking System v1.0 contains a SQL injection vulnerability in the admin booking details page that allows attackers to execute arbitrar...
Jun 2, 2022Online Car Wash Booking System v1.0 contains a SQL injection vulnerability in the admin panel's user management page. Attackers can exploit this to ex...
Jun 2, 2022Online Car Wash Booking System v1.0 contains a SQL injection vulnerability in the delete_vehicle function that allows attackers to execute arbitrary S...
Jun 2, 2022Online Car Wash Booking System v1.0 contains a SQL injection vulnerability in the admin vehicle management interface that allows attackers to execute ...
Jun 2, 2022CVE-2022-31352 is a critical SQL injection vulnerability in Online Car Wash Booking System v1.0 that allows attackers to execute arbitrary SQL command...
Jun 2, 2022Online Car Wash Booking System v1.0 contains a SQL injection vulnerability in the get_vehicle_service endpoint that allows attackers to execute arbitr...
Jun 2, 2022Online Ordering System version 2.3.2 contains a SQL injection vulnerability in the products parameter that allows attackers to execute arbitrary SQL c...
Jun 2, 2022CVE-2022-31329 is a critical SQL injection vulnerability in Online Ordering System by janobe version 2.3.2 that allows attackers to execute arbitrary ...
Jun 2, 2022Online Ordering System 2.3.2 contains a SQL injection vulnerability in the /ordering/admin/stockin/loaddata.php endpoint that allows attackers to exec...
Jun 2, 2022Online Ordering System 2.3.2 contains a SQL injection vulnerability in the admin user management interface that allows attackers to execute arbitrary ...
Jun 2, 2022EliteCMS v1.01 contains a SQL injection vulnerability in the admin/edit_post.php endpoint that allows attackers to execute arbitrary SQL commands. Thi...
Jun 2, 2022EliteCMS v1.01 contains a SQL injection vulnerability in the /admin/add_sidebar.php endpoint that allows attackers to execute arbitrary SQL commands. ...
Jun 2, 2022CVE-2022-30816 is a critical SQL injection vulnerability in elitecms 1.01 that allows attackers to execute arbitrary SQL commands via the /admin/edit_...
Jun 2, 2022Online Ordering System 1.0 contains a SQL injection vulnerability in the admin/vieworders.php endpoint that allows attackers to execute arbitrary SQL ...
Jun 2, 2022CVE-2022-30511 is a critical SQL injection vulnerability in School Dormitory Management System 1.0 that allows attackers to execute arbitrary SQL comm...
Jun 2, 2022CVE-2022-30481 is a critical SQL injection vulnerability in Food Order and Table Reservation System 1.0 that allows attackers to execute arbitrary SQL...
Jun 2, 2022Badminton Center Management System V1.0 contains an SQL injection vulnerability in the court rental status update functionality. Attackers can exploit...
Jun 2, 2022CVE-2022-30352 is a SQL injection vulnerability in phpABook 0.9i that allows attackers to execute arbitrary SQL commands via the 'auth_user' parameter...
Jun 2, 2022This vulnerability allows attackers to execute arbitrary SQL commands via the 'id' parameter in single.php in Responsive Online Blog v1.0. This can le...
Jun 2, 2022CVE-2021-44095 is a critical SQL injection vulnerability in ProjectWorlds Hospital Management System in PHP 1.0 that allows remote attackers to execut...
Jun 2, 2022CVE-2021-44097 is a critical SQL injection vulnerability in EGavilan Media's Contact-Form-With-Messages-Entry-Management plugin version 1.0. Attackers...
Jun 2, 2022CVE-2021-26634 is a critical vulnerability in Maxboard software that allows SQL injection and file upload attacks due to insufficient input validation...
Jun 2, 2022This SQL injection vulnerability in zzcms 2019 allows attackers to execute arbitrary SQL commands through the id parameter in /admin/dl_sendsms.php. T...
Jun 2, 2022This SQL injection vulnerability in zzcms 2019 allows attackers to execute arbitrary SQL commands via the id parameter in dl/dl_print.php. Any system ...
Jun 2, 2022This vulnerability allows attackers to execute arbitrary SQL commands on WordPress sites using the StaffList plugin before version 3.1.5. The SQL inje...
May 30, 2022CVE-2022-30493 is a critical SQL injection vulnerability in oretnom23 Automotive Shop Management System v1.0 that allows remote attackers to extract d...
May 26, 2022CVE-2022-30500 is a SQL injection vulnerability in Jfinal CMS 5.1.0 that allows attackers to execute arbitrary SQL commands through crafted inputs. Th...
May 26, 2022CVE-2022-29660 is a critical SQL injection vulnerability in CSCMS Music Portal System v4.2 that allows attackers to execute arbitrary SQL commands via...
May 26, 2022CVE-2022-30838 is a critical SQL injection vulnerability in Covid-19 Travel Pass Management System v1.0 that allows attackers to execute arbitrary SQL...
May 24, 2022Water Billing Management System v1.0 contains a SQL injection vulnerability in the delete_client function that allows attackers to execute arbitrary S...
May 24, 2022Merchandise Online Store 1.0 contains a SQL injection vulnerability in the delete_product function that allows attackers to execute arbitrary SQL comm...
May 24, 2022CVE-2022-0781 is an unauthenticated SQL injection vulnerability in the Nirweb Support WordPress plugin. Attackers can execute arbitrary SQL commands t...
May 23, 2022This vulnerability allows attackers to execute arbitrary SQL commands through the username field in the admin login page of Covid-19 Directory on Vacc...
May 20, 2022This CVE describes a SQL injection vulnerability in ChatBot Application with a Suggestion Feature 1.0. Attackers can inject malicious SQL commands via...
May 20, 2022CVE-2021-37413 is a critical SQL injection vulnerability in GRANDCOM DynWEB's admin login interface that allows unauthenticated attackers to execute a...
May 19, 2022CVE-2022-30599 is a critical SQL injection vulnerability in Moodle's badges functionality that allows attackers to execute arbitrary SQL commands. Thi...
May 18, 2022CVE-2022-30052 is a critical SQL injection vulnerability in Home Clean Service System 1.0's password parameter, allowing attackers to execute arbitrar...
May 17, 2022CVE-2022-30054 is a critical SQL injection vulnerability in Covid 19 Travel Pass Management 1.0 that allows attackers to execute arbitrary SQL command...
May 17, 2022Metasonic Doc WebClient versions 7.0.14.0, 7.0.12.0, and 7.0.3.0 contain a SQL injection vulnerability in the username field when SSO or System authen...
May 16, 2022CVE-2022-0867 is a critical SQL injection vulnerability in the Pricing Table WordPress plugin that allows unauthenticated attackers to execute arbitra...
May 16, 2022CVE-2022-30011 is a critical SQL injection vulnerability in HMS 1.0's appointment.php endpoint that allows attackers to execute arbitrary SQL commands...
May 16, 2022CVE-2022-30765 is a SQL injection vulnerability in Calibre-Web's user table functionality that allows attackers to execute arbitrary SQL commands. Thi...
May 16, 2022ERP-Pro v3.7.5 contains a SQL injection vulnerability in the SysEveMenuAuthPointMapper.xml component that allows attackers to execute arbitrary SQL co...
May 15, 2022Hospital Management System v1.0 contains a SQL injection vulnerability in the delid parameter at viewtreatmentrecord.php that allows attackers to exec...
May 15, 2022CVE-2022-30413 is a critical SQL injection vulnerability in Covid-19 Travel Pass Management System v1.0 that allows attackers to execute arbitrary SQL...
May 13, 2022Merchandise Online Store v1.0 contains a SQL injection vulnerability in the delete_inventory function that allows attackers to execute arbitrary SQL c...
May 13, 2022Merchandise Online Store v1.0 contains a SQL injection vulnerability in the delete_featured function that allows attackers to execute arbitrary SQL co...
May 13, 2022About SQL Injection (CWE-89)
The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.
Our database tracks 4,717 CVEs classified as CWE-89, with 2,067 rated critical and 1,999 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.
External reference: View CWE-89 on MITRE CWE →
Monitor SQL Injection Vulnerabilities
Get alerted when new SQL Injection CVEs affect your infrastructure.
Start Monitoring Free