CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,776
Total CVEs
2,123
Critical
2,001
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
246
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 130
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,776)

CVE-2022-0412
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks against WordPress sites using vulnerable versions of the TI WooCo...

Feb 28, 2022
CVE-2022-25003
9.8

This vulnerability allows attackers to execute arbitrary SQL commands via the id parameter in the /admin/doctors/view_doctor.php endpoint of Hospital ...

Feb 24, 2022
CVE-2022-25148
9.8

This SQL injection vulnerability in the WP Statistics WordPress plugin allows unauthenticated attackers to execute arbitrary SQL queries. Attackers ca...

Feb 24, 2022
CVE-2022-0651
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites running the WP Statistics plugin. Attackers ca...

Feb 24, 2022
CVE-2022-25404
9.8

This CVE describes a SQL injection vulnerability in Tongda2000 v11.10's delete.php file via the DELETE_STR parameter, allowing attackers to execute ar...

Feb 24, 2022
CVE-2022-25406
9.8

This CVE describes a SQL injection vulnerability in Tongda2000 v11.10's delete_query.php file via the DELETE_STR parameter. Attackers can execute arbi...

Feb 24, 2022
CVE-2021-44567
9.8

An unauthenticated SQL injection vulnerability in RosarioSIS allows attackers to execute arbitrary SQL commands via the votes parameter in PortalPolls...

Feb 24, 2022
CVE-2021-44610
9.8

CVE-2021-44610 allows attackers to execute arbitrary SQL commands via multiple parameters in bloofoxCMS admin interface. This affects all bloofoxCMS i...

Feb 24, 2022
CVE-2021-46110
9.8

Online Shopping Portal v3.1 contains time-based SQL injection vulnerabilities in the email and contactno parameters, allowing attackers to execute arb...

Feb 18, 2022
CVE-2022-25322
9.8

ZEROF Web Server 2.0 contains a SQL injection vulnerability in the /HandleEvent endpoint that allows attackers to execute arbitrary SQL commands. This...

Feb 18, 2022
CVE-2021-44868
9.8

CVE-2021-44868 is a SQL injection vulnerability in ming-soft MCMS v5.1 that allows attackers to execute arbitrary SQL commands through the /ms/cms/con...

Feb 17, 2022
CVE-2022-22880
9.8

Jeecg-boot v3.0 contains a SQL injection vulnerability in the /jeecg-boot/sys/user/queryUserByDepId endpoint via the code parameter. This allows attac...

Feb 16, 2022
CVE-2021-3242
9.8

CVE-2021-3242 is a SQL injection vulnerability in DuxCMS v3.1.3 that allows attackers to execute arbitrary SQL commands via the s/tools/SendTpl/index?...

Feb 16, 2022
CVE-2022-0513
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites running the WP Statistics plugin with 'Record ...

Feb 16, 2022
CVE-2022-23336
9.8

S-CMS v5.0 contains a SQL injection vulnerability in the member_pay.php file through the O_id parameter. This allows attackers to execute arbitrary SQ...

Feb 14, 2022
CVE-2022-23902
9.8

This CVE describes a SQL injection vulnerability in Tongda2000 v11.10's export_data.php file via the d_name parameter. Attackers can execute arbitrary...

Feb 14, 2022
CVE-2021-25114
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites running vulnerable versions of the Paid Member...

Feb 7, 2022
CVE-2022-24219
9.8

CVE-2022-24219 is a SQL injection vulnerability in eliteCMS v1.0 that allows attackers to execute arbitrary SQL commands via the /admin/edit_page.php ...

Feb 1, 2022
CVE-2022-24221
9.8

CVE-2022-24221 is a SQL injection vulnerability in eliteCMS v1.0 that allows attackers to execute arbitrary SQL commands via the /admin/functions/func...

Feb 1, 2022
CVE-2022-24223
9.8

AtomCMS v2.0 contains a SQL injection vulnerability in the admin login page that allows attackers to execute arbitrary SQL commands. This affects all ...

Feb 1, 2022
CVE-2021-43509
9.8

This CVE describes a SQL injection vulnerability in Simple Client Management System 1.0 that allows attackers to execute arbitrary SQL commands via th...

Feb 1, 2022
CVE-2021-24762
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites running the Perfect Survey plugin before versi...

Feb 1, 2022
CVE-2022-24263
9.8

CVE-2022-24263 is a SQL injection vulnerability in Hospital Management System v4.0 that allows attackers to execute arbitrary SQL commands via the ema...

Jan 31, 2022
CVE-2021-46444
9.8

CVE-2021-46444 is a SQL injection vulnerability in H.H.G Multistore's admin interface that allows attackers to execute arbitrary SQL commands. This af...

Jan 28, 2022
CVE-2021-46446
9.8

CVE-2021-46446 is a SQL injection vulnerability in H.H.G Multistore's admin interface that allows attackers to execute arbitrary SQL commands. This af...

Jan 28, 2022
CVE-2021-46448
9.8

This vulnerability allows attackers to execute arbitrary SQL commands via the customers.php admin endpoint in H.H.G Multistore. Attackers can potentia...

Jan 28, 2022
CVE-2021-41609
9.8

This is a critical SQL injection vulnerability in SelectSurvey.NET that allows unauthenticated remote attackers to extract sensitive data from the bac...

Jan 28, 2022
CVE-2022-22294
9.8

CVE-2022-22294 is a critical SQL injection vulnerability in ZFAKA e-commerce software that allows unauthenticated attackers to execute arbitrary SQL c...

Jan 28, 2022
CVE-2020-25905
9.8

This SQL injection vulnerability in Sourcecodester Mobile Shop System 1.0 allows attackers to execute arbitrary SQL commands via the email parameter i...

Jan 28, 2022
CVE-2021-44249
9.8

Online Motorcycle Rental System 1.0 has a blind time-based SQL injection vulnerability in its login portal that allows attackers to extract database c...

Jan 28, 2022
CVE-2021-46377
9.8

CVE-2021-46377 is a SQL injection vulnerability in CSZCMS 1.2.9 that allows attackers to execute arbitrary SQL commands through the Member.php control...

Jan 27, 2022
CVE-2022-0362
9.8

CVE-2022-0362 is a critical SQL injection vulnerability in showdoc documentation software that allows attackers to execute arbitrary SQL commands. Thi...

Jan 26, 2022
CVE-2022-0332
9.8

This SQL injection vulnerability in Moodle's H5P activity web service allows attackers to execute arbitrary SQL commands. It affects Moodle installati...

Jan 25, 2022
CVE-2021-46089
9.8

CVE-2021-46089 is a critical SQL injection vulnerability in JeecgBoot 3.0 that allows attackers to execute arbitrary SQL commands with root database p...

Jan 25, 2022
CVE-2021-45802
9.8

CVE-2021-45802 is a critical SQL injection vulnerability in MartDevelopers iResturant 1.0 that allows attackers to execute arbitrary SQL commands thro...

Jan 25, 2022
CVE-2021-46024
9.8

This CVE describes an unauthenticated SQL injection vulnerability in Projectworlds online-shopping-webvsite-in-php version 1.0. Attackers can exploit ...

Jan 23, 2022
CVE-2022-23363
9.8

Online Banking System v1.0 contains a SQL injection vulnerability in index.php that allows attackers to execute arbitrary SQL commands. This affects a...

Jan 21, 2022
CVE-2022-23365
9.8

CVE-2022-23365 is a critical SQL injection vulnerability in HMS v1.0's doctorlogin.php that allows attackers to execute arbitrary SQL commands. This a...

Jan 21, 2022
CVE-2021-40595
9.8

This SQL injection vulnerability in the Online Leave Management System allows attackers to execute arbitrary SQL commands via the username parameter i...

Jan 21, 2022
CVE-2021-40247
9.8

This SQL injection vulnerability in the Budget and Expense Tracker System allows attackers to execute arbitrary SQL commands through the username fiel...

Jan 21, 2022
CVE-2021-46308
9.8

This SQL injection vulnerability in Sourcecodester Online Railway Reservation System 1.0 allows attackers to execute arbitrary SQL commands via the 's...

Jan 21, 2022
CVE-2021-46200
9.8

This SQL injection vulnerability in Simple Music Cloud Community System 1.0 allows attackers to execute arbitrary SQL commands via the email parameter...

Jan 21, 2022
CVE-2021-46307
9.8

This SQL injection vulnerability in Projectworlds Online Examination System 1.0 allows attackers to execute arbitrary SQL commands via the eid paramet...

Jan 21, 2022
CVE-2021-46061
9.8

This CVE describes a critical SQL injection vulnerability in the Computer and Mobile Repair Shop Management System (RSMS) 1.0. Attackers can exploit t...

Jan 20, 2022
CVE-2021-44090
9.8

This SQL injection vulnerability in Sourcecodester Online Reviewer System 1.0 allows attackers to execute arbitrary SQL commands via the password para...

Jan 20, 2022
CVE-2021-44244
9.8

CVE-2021-44244 is an SQL injection vulnerability in the login.php file of Sourcecodester Logistic Hub Parcel's Management System 1.0. Attackers can in...

Jan 20, 2022
CVE-2021-46204
9.8

Taocms v3.0.2 contains both an arbitrary file read vulnerability via the path parameter and an SQL injection vulnerability in Article.php. This allows...

Jan 19, 2022
CVE-2022-23305
9.8

CVE-2022-23305 is an SQL injection vulnerability in Log4j 1.2.x's JDBCAppender that allows attackers to execute arbitrary SQL queries by injecting mal...

Jan 18, 2022
CVE-2022-22055
9.8

CVE-2022-22055 is a critical SQL injection vulnerability in the Le-yan dental management system login page. Unauthenticated attackers can execute arbi...

Jan 14, 2022
CVE-2020-28102
9.8

CVE-2020-28102 is a critical SQL injection vulnerability in cscms v4.1 that allows attackers to execute arbitrary SQL commands via the 'js_del' functi...

Jan 11, 2022

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,776 CVEs classified as CWE-89, with 2,123 rated critical and 2,001 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free