CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,787
Total CVEs
2,134
Critical
2,001
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
246
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 130
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,787)

CVE-2021-24949
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the 'WP Search Filters' widget in The Plus Addons for Elementor Pro Word...

Jan 10, 2022
CVE-2021-45334
9.8

CVE-2021-45334 is a critical SQL injection vulnerability in Sourcecodester Online Thesis Archiving System 1.0 that allows unauthenticated attackers to...

Jan 10, 2022
CVE-2021-45814
9.8

CVE-2021-45814 is a critical SQL injection vulnerability in Nettmp NNT 5.1 that allows attackers to bypass authentication and gain administrative acce...

Dec 28, 2021
CVE-2021-43155
9.8

CVE-2021-43155 is a critical SQL injection vulnerability in Projectsworlds Online Book Store PHP v1.0 that allows attackers to execute arbitrary SQL c...

Dec 22, 2021
CVE-2021-43157
9.8

CVE-2021-43157 is a critical SQL injection vulnerability in Projectsworlds Online Shopping System PHP 1.0 that allows attackers to execute arbitrary S...

Dec 22, 2021
CVE-2021-43628
9.8

CVE-2021-43628 is a critical SQL injection vulnerability in Projectworlds Hospital Management System v1.0 that allows attackers to execute arbitrary S...

Dec 22, 2021
CVE-2021-43631
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the appointment_no parameter in payment.php. It affects Hospital Managem...

Dec 22, 2021
CVE-2021-45252
9.8

CVE-2021-45252 is a critical SQL injection vulnerability in Simple Forum-Discussion System 1.0 that allows attackers to execute arbitrary SQL commands...

Dec 21, 2021
CVE-2021-45255
9.8

This CVE describes a critical SQL injection vulnerability in Video Sharing Website 1.0's ajax.php email parameter. Attackers can execute arbitrary SQL...

Dec 21, 2021
CVE-2021-24849
9.8

CVE-2021-24849 is a critical SQL injection vulnerability in the WCFM Marketplace WordPress plugin that allows attackers to execute arbitrary SQL comma...

Dec 21, 2021
CVE-2021-44350
9.8

This SQL injection vulnerability in ThinkPHP5 allows attackers to execute arbitrary SQL commands through the parseOrder function. It affects all Think...

Dec 15, 2021
CVE-2021-44653
9.8

CVE-2021-44653 is a SQL injection vulnerability in Online Magazine Management System 1.0 that allows authentication bypass in the admin panel login fo...

Dec 15, 2021
CVE-2021-42945
9.8

This SQL injection vulnerability in ZZCMS 2021 allows attackers to execute arbitrary SQL commands through the askbigclassid parameter in /admin/ask.ph...

Dec 15, 2021
CVE-2021-42064
9.8

This vulnerability allows attackers to execute SQL injection attacks on SAP Commerce systems configured with Oracle databases when using parameterized...

Dec 14, 2021
CVE-2021-44966
9.8

This vulnerability allows attackers to bypass authentication in PHPGURUKUL Employee Record Management System 1.2 via SQL injection in index.php. Attac...

Dec 13, 2021
CVE-2021-24863
9.8

This vulnerability allows attackers to perform SQL injection attacks by manipulating the User-Agent header in requests to WordPress sites using the St...

Dec 13, 2021
CVE-2021-24946
9.8

This is an unauthenticated SQL injection vulnerability in the Modern Events Calendar Lite WordPress plugin. Attackers can exploit it by sending specia...

Dec 13, 2021
CVE-2021-43608
9.8

CVE-2021-43608 is a SQL injection vulnerability in Doctrine DBAL where offset and length parameters in LIMIT clauses aren't properly cast to integers....

Dec 9, 2021
CVE-2021-3817
9.8

CVE-2021-3817 is an SQL injection vulnerability in WBCE CMS that allows attackers to execute arbitrary SQL commands. This can lead to authentication b...

Dec 9, 2021
CVE-2021-41063
9.8

An unauthenticated SQL injection vulnerability in Aanderaa GeoView Webservice allows attackers to execute arbitrary SQL commands on the database. This...

Dec 8, 2021
CVE-2021-29114
9.8

A critical SQL injection vulnerability in Esri ArcGIS Server feature services allows remote unauthenticated attackers to execute arbitrary SQL command...

Dec 7, 2021
CVE-2021-31632
9.8

CVE-2021-31632 is a critical SQL injection vulnerability in b2evolution CMS v7.2.3 that allows attackers to execute arbitrary SQL commands via the cfq...

Dec 6, 2021
CVE-2021-24866
9.8

This SQL injection vulnerability in the WP Data Access WordPress plugin allows attackers to delete arbitrary database tables by exploiting unsanitized...

Dec 6, 2021
CVE-2021-24931
9.8

This vulnerability allows attackers to execute arbitrary SQL commands on WordPress sites running the Secure Copy Content Protection and Content Lockin...

Dec 6, 2021
CVE-2021-24943
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites running vulnerable versions of the Registrati...

Dec 6, 2021
CVE-2021-43035
9.8

Two unauthenticated SQL injection vulnerabilities in Kaseya Unitrends Backup Appliance allow attackers to execute arbitrary SQL queries as the postgre...

Dec 6, 2021
CVE-2021-35414
9.8

CVE-2021-35414 is an unauthenticated SQL injection vulnerability in Chamilo LMS v1.11.x that allows attackers to execute arbitrary SQL commands via th...

Dec 3, 2021
CVE-2021-44348
9.8

This CVE describes a SQL injection vulnerability in TuziCMS v2.0.6 that allows attackers to execute arbitrary SQL commands via the 'id' parameter in t...

Dec 3, 2021
CVE-2021-44347
9.8

This CVE describes a SQL injection vulnerability in TuziCMS v2.0.6 that allows attackers to execute arbitrary SQL commands through the guestbook contr...

Dec 3, 2021
CVE-2021-43679
9.8

CVE-2021-43679 is a critical SQL injection vulnerability in ECShop v2.7.3's API client component that allows attackers to execute arbitrary SQL comman...

Dec 2, 2021
CVE-2021-43451
9.8

This CVE describes a SQL injection vulnerability in PHPGURUKUL Employee Record Management System 1.2. Attackers can inject malicious SQL commands via ...

Dec 1, 2021
CVE-2021-44280
9.8

CVE-2021-44280 is a critical SQL injection vulnerability in Attendance Management System 1.0 that allows attackers to execute arbitrary SQL commands t...

Dec 1, 2021
CVE-2021-41678
9.8

A SQL injection vulnerability in openSIS version 8.0 allows attackers to execute arbitrary SQL commands through the staff[TITLE] parameter in Staff.ph...

Nov 30, 2021
CVE-2021-41677
9.8

A SQL injection vulnerability in openSIS version 8.0 allows attackers to execute arbitrary SQL commands through the Grade parameter. This affects all ...

Nov 30, 2021
CVE-2021-44427
9.8

An unauthenticated SQL injection vulnerability in Rosario Student Information System (rosariosis) allows remote attackers to execute arbitrary Postgre...

Nov 29, 2021
CVE-2021-24915
9.8

This vulnerability in the Contest Gallery WordPress plugin allows unauthenticated attackers to perform SQL injection attacks and retrieve all register...

Nov 29, 2021
CVE-2021-44026
9.8

This SQL injection vulnerability in Roundcube webmail allows attackers to execute arbitrary SQL commands via search or search_params parameters. It af...

Nov 19, 2021
CVE-2021-41931
9.8

CVE-2021-41931 is a SQL injection vulnerability in a Recruitment Management System that allows attackers to execute arbitrary SQL commands through the...

Nov 17, 2021
CVE-2021-3958
9.8

CVE-2021-3958 is a blind SQL injection vulnerability in Ipack Automation Systems SCADA software that allows attackers to execute arbitrary SQL command...

Nov 16, 2021
CVE-2021-41765
9.8

This SQL injection vulnerability in ResourceSpace allows unauthenticated attackers to execute arbitrary SQL commands, potentially exposing the entire ...

Nov 15, 2021
CVE-2021-42580
9.8

CVE-2021-42580 is a critical vulnerability in Sourcecodester Online Learning System 2.0 that combines SQL injection authentication bypass with authent...

Nov 15, 2021
CVE-2021-41081
9.8

CVE-2021-41081 is a critical SQL injection vulnerability in Zoho ManageEngine Network Configuration Manager that allows attackers to execute arbitrary...

Nov 11, 2021
CVE-2021-24827
9.8

CVE-2021-24827 is an unauthenticated SQL injection vulnerability in the Asgaros Forum WordPress plugin. Attackers can exploit this to execute arbitrar...

Nov 8, 2021
CVE-2021-24731
9.8

This SQL injection vulnerability in the Registration Forms WordPress plugin allows attackers to execute arbitrary SQL commands via the wp-json/pie/v1/...

Nov 8, 2021
CVE-2021-34684
9.8

CVE-2021-34684 is a critical SQL injection vulnerability in Hitachi Vantara Pentaho Business Analytics that allows unauthenticated attackers to execut...

Nov 8, 2021
CVE-2021-42077
9.8

CVE-2021-42077 is a SQL injection vulnerability in PHP Event Calendar that allows attackers to execute arbitrary SQL commands through the username par...

Nov 8, 2021
CVE-2020-22225
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the pjActionLoadForm function in Stivasoft's Phpjabbers Fundraising Scri...

Nov 5, 2021
CVE-2020-22223
9.8

CVE-2020-22223 is a SQL injection vulnerability in Stivasoft's Phpjabbers Fundraising Script v1.0 that allows attackers to execute arbitrary SQL comma...

Nov 5, 2021
CVE-2021-42667
9.8

CVE-2021-42667 is a critical SQL injection vulnerability in Sourcecodester's Online Event Booking and Reservation System in PHP. It allows attackers t...

Nov 5, 2021
CVE-2021-42665
9.8

CVE-2021-42665 is an SQL injection vulnerability in the Engineers Online Portal PHP application that allows attackers to bypass authentication via the...

Nov 5, 2021

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,787 CVEs classified as CWE-89, with 2,134 rated critical and 2,001 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free