CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,730
Total CVEs
2,077
Critical
2,001
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
246
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 130
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,730)

CVE-2022-23797
9.8

CVE-2022-23797 is a critical SQL injection vulnerability in Joomla! CMS that allows attackers to execute arbitrary SQL commands through inadequate fil...

Mar 30, 2022
CVE-2020-24769
9.8

This SQL injection vulnerability in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the classes parameter in takeconfirm.ph...

Mar 30, 2022
CVE-2022-26666
9.8

Delta Electronics DIAEnergie versions before 1.8.02.004 contain a blind SQL injection vulnerability in HandlerECC.ashx that allows attackers to execut...

Mar 29, 2022
CVE-2022-26836
9.8

Delta Electronics DIAEnergie versions before 1.8.02.004 contain a blind SQL injection vulnerability in the HandlerExport.ashx/Calendar endpoint. This ...

Mar 29, 2022
CVE-2022-26887
9.8

Delta Electronics DIAEnergie versions prior to 1.8.02.004 contain a blind SQL injection vulnerability in DIAE_loopmapHandler.ashx that allows attacker...

Mar 29, 2022
CVE-2022-0923
9.8

Delta Electronics DIAEnergie versions prior to 1.8.02.004 contain a blind SQL injection vulnerability in HandlerDialog_KID.ashx. This allows attackers...

Mar 29, 2022
CVE-2022-25980
9.8

Delta Electronics DIAEnergie versions before 1.8.02.004 contain a blind SQL injection vulnerability in HandlerCommon.ashx that allows attackers to exe...

Mar 29, 2022
CVE-2022-26059
9.8

Delta Electronics DIAEnergie versions prior to 1.8.02.004 contain a blind SQL injection vulnerability in the GetQueryData function. This allows attack...

Mar 29, 2022
CVE-2022-26069
9.8

Delta Electronics DIAEnergie versions before 1.8.02.004 contain a blind SQL injection vulnerability in HandlerPage_KID.ashx. This allows attackers to ...

Mar 29, 2022
CVE-2022-26349
9.8

Delta Electronics DIAEnergie versions prior to 1.8.02.004 contain a blind SQL injection vulnerability in the DIAE_eccoefficientHandler.ashx endpoint. ...

Mar 29, 2022
CVE-2022-0784
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Title Experiments Free plugin. Atta...

Mar 28, 2022
CVE-2022-0846
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks against WordPress sites running the SpeakOut! Email Petitions plu...

Mar 28, 2022
CVE-2021-25070
9.8

This SQL injection vulnerability in the Block Bad Bots WordPress plugin allows attackers to execute arbitrary SQL commands by manipulating the User-Ag...

Mar 28, 2022
CVE-2022-0479
9.8

This vulnerability in the Popup Builder WordPress plugin allows SQL injection and reflected XSS attacks. Attackers can exploit it by sending malicious...

Mar 28, 2022
CVE-2022-23882
9.8

CVE-2022-23882 is a SQL injection vulnerability in TuziCMS 2.0.6 that allows attackers to execute arbitrary SQL commands through the BannerController ...

Mar 28, 2022
CVE-2021-44617
9.8

This CVE describes a SQL injection vulnerability in the Ramo plugin for GLPI 9.4.6 that allows attackers to execute arbitrary SQL commands via the idu...

Mar 28, 2022
CVE-2022-26268
9.8

CVE-2022-26268 is a SQL injection vulnerability in Xiaohuanxiong v1.0 that allows attackers to execute arbitrary SQL commands via the id parameter in ...

Mar 28, 2022
CVE-2021-26599
9.8

CVE-2021-26599 is a SQL injection vulnerability in ImpressCMS's include/findusers.php groups parameter. Attackers can execute arbitrary SQL commands t...

Mar 28, 2022
CVE-2021-43084
9.8

This SQL injection vulnerability in Dreamer CMS 4.0.0 allows attackers to execute arbitrary SQL commands via the tableName parameter. This can lead to...

Mar 24, 2022
CVE-2021-43700
9.8

CVE-2021-43700 is a SQL injection vulnerability in ApiManager 1.1 that allows attackers to execute arbitrary SQL commands through the /index.php?act=a...

Mar 24, 2022
CVE-2022-25222
9.8

Money Transfer Management System Version 1.0 contains unauthenticated SQL injection vulnerabilities in two administrative endpoints. Attackers can exe...

Mar 23, 2022
CVE-2021-43735
9.8

CVE-2021-43735 is a SQL injection vulnerability in CmsWing CMS that allows attackers to execute arbitrary SQL commands through the 'behavior rule' par...

Mar 23, 2022
CVE-2022-25517
9.8

CVE-2022-25517 is a SQL injection vulnerability in MyBatis Plus v3.4.3 that allows attackers to execute arbitrary SQL commands through the Column para...

Mar 22, 2022
CVE-2021-43650
9.8

CVE-2021-43650 is a SQL injection vulnerability in WebRun 3.6.0.42 that allows attackers to manipulate database queries via the P_0 parameter during l...

Mar 22, 2022
CVE-2022-26283
9.8

Simple Subscription Website v1.0 contains a SQL injection vulnerability in the view_plan endpoint's id parameter. Attackers can exploit this to extrac...

Mar 21, 2022
CVE-2022-26285
9.8

Simple Subscription Website v1.0 contains a SQL injection vulnerability in the apply endpoint's id parameter that allows attackers to execute arbitrar...

Mar 21, 2022
CVE-2022-0694
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites using the Advanced Booking Calendar plugin bef...

Mar 21, 2022
CVE-2022-0747
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Infographic Maker plugin before ver...

Mar 21, 2022
CVE-2022-25505
9.8

CVE-2022-25505 is a critical SQL injection vulnerability in Taocms v3.0.2 that allows attackers to execute arbitrary SQL commands via the id parameter...

Mar 21, 2022
CVE-2022-25490
9.8

CVE-2022-25490 is a SQL injection vulnerability in HMS v1.0 that allows attackers to execute arbitrary SQL commands via the editid parameter in depart...

Mar 15, 2022
CVE-2022-25492
9.8

CVE-2022-25492 is a critical SQL injection vulnerability in HMS v1.0 that allows attackers to execute arbitrary SQL commands via the medicineid parame...

Mar 15, 2022
CVE-2022-25494
9.8

Online Banking System v1.0 contains a SQL injection vulnerability in the staff_login.php page that allows attackers to execute arbitrary SQL commands....

Mar 15, 2022
CVE-2022-24752
9.8

SyliusGridBundle versions before 1.10.1 and 1.11-rc2 have a SQL injection vulnerability where user-controlled sorting parameters are passed directly t...

Mar 15, 2022
CVE-2022-0658
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites running vulnerable versions of the CommonsBoo...

Mar 14, 2022
CVE-2021-25007
9.8

This vulnerability allows attackers to execute arbitrary SQL commands on WordPress sites using the MOLIE plugin. It affects all WordPress installation...

Mar 14, 2022
CVE-2022-0169
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Photo Gallery by 10Web plugin. Atta...

Mar 14, 2022
CVE-2022-0254
9.8

This vulnerability allows attackers to perform SQL injection attacks on WordPress sites using the Zero Spam plugin before version 5.2.11. Attackers ca...

Mar 14, 2022
CVE-2022-24606
9.8

CVE-2022-24606 is a SQL injection vulnerability in Luocms v2.0 that allows attackers to execute arbitrary SQL commands through the /admin/news/sort_ok...

Mar 10, 2022
CVE-2022-24602
9.8

CVE-2022-24602 is a SQL injection vulnerability in Luocms v2.0's news_mod.php admin endpoint that allows attackers to execute arbitrary SQL commands. ...

Mar 10, 2022
CVE-2022-24604
9.8

CVE-2022-24604 is a SQL injection vulnerability in Luocms v2.0 that allows attackers to execute arbitrary SQL commands via the /admin/link/link_mod.ph...

Mar 10, 2022
CVE-2022-24600
9.8

CVE-2022-24600 is a critical SQL injection vulnerability in Luocms v2.0's admin login page that allows attackers to bypass authentication and gain adm...

Mar 10, 2022
CVE-2022-0349
9.8

This vulnerability allows unauthenticated attackers to perform blind SQL injection attacks on WordPress sites running NotificationX plugin versions be...

Mar 7, 2022
CVE-2022-0434
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks against WordPress sites using the Page View Count plugin. Attacke...

Mar 7, 2022
CVE-2022-26201
9.8

CVE-2022-26201 is a SQL injection vulnerability in Victor CMS v1.0 that allows attackers to execute arbitrary SQL commands through unsanitized user in...

Mar 4, 2022
CVE-2022-23898
9.8

MCMS v5.2.5 contains a SQL injection vulnerability in the categoryId parameter that allows attackers to execute arbitrary SQL commands. This affects a...

Mar 3, 2022
CVE-2022-25125
9.8

MCMS v5.2.4 contains a SQL injection vulnerability in the search.do endpoint at /mdiy/dict/listExcludeApp. This allows attackers to execute arbitrary ...

Mar 3, 2022
CVE-2022-25394
9.8

This vulnerability allows attackers to execute arbitrary SQL commands via the cid parameter in the customer-add.php file of Medical Store Management S...

Mar 2, 2022
CVE-2022-25396
9.8

This CVE describes a SQL injection vulnerability in Cosmetics and Beauty Product Online Store v1.0 through the search parameter. Attackers can execute...

Mar 2, 2022
CVE-2022-25399
9.8

Simple Real Estate Portal System v1.0 contains a SQL injection vulnerability in the id parameter that allows attackers to execute arbitrary SQL comman...

Mar 2, 2022
CVE-2022-0412
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks against WordPress sites using vulnerable versions of the TI WooCo...

Feb 28, 2022

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,730 CVEs classified as CWE-89, with 2,077 rated critical and 2,001 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free