CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,802
Total CVEs
2,140
Critical
2,010
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
246
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 131
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,802)

CVE-2021-43140
9.8

CVE-2021-43140 is a critical SQL injection vulnerability in Simple Subscription Website 1.0 that allows attackers to execute arbitrary SQL commands th...

Nov 3, 2021
CVE-2020-24000
9.8

This SQL injection vulnerability in eyoucms v1.4.7 allows attackers to execute arbitrary SQL commands via the tid parameter in index.php. Attackers ca...

Nov 3, 2021
CVE-2021-43130
9.8

This CVE describes a critical SQL injection vulnerability in the Sourcecodester Customer Relationship Management System (CRM) version 1.0. Attackers c...

Nov 3, 2021
CVE-2020-23685
9.8

This SQL injection vulnerability in 188Jianzhan v2.1.0 allows attackers to execute arbitrary SQL commands via the username parameter in login.php. Att...

Nov 2, 2021
CVE-2021-26739
9.8

This SQL injection vulnerability in millken doyocms 2.3 allows attackers to execute arbitrary SQL commands via the attribute parameter in pay.php. Att...

Nov 1, 2021
CVE-2021-41676
9.8

CVE-2021-41676 is an SQL injection vulnerability in the Pharmacy Point of Sale System 1.0 that allows attackers to execute arbitrary SQL commands thro...

Oct 29, 2021
CVE-2020-21250
9.8

CVE-2020-21250 is an arbitrary file upload vulnerability in CSZ CMS v1.2.4 that allows attackers to upload malicious files to the server. This affects...

Oct 27, 2021
CVE-2020-24932
9.8

This SQL injection vulnerability in Sourcecodester Complaint Management System 1.0 allows attackers to execute arbitrary SQL commands via the cid para...

Oct 27, 2021
CVE-2021-37371
9.8

CVE-2021-37371 is an unauthenticated SQL injection vulnerability in the Online Student Admission System 1.0 admin login page. Attackers can bypass aut...

Oct 26, 2021
CVE-2021-42258
9.8

CVE-2021-42258 is a critical SQL injection vulnerability in BQE BillQuick Web Suite that allows unauthenticated attackers to execute arbitrary SQL com...

Oct 22, 2021
CVE-2020-28960
9.8

Chichen Tech CMS v1.0 contains SQL injection vulnerabilities in product_list.php via id and cid parameters. Attackers can execute arbitrary SQL comman...

Oct 22, 2021
CVE-2021-42169
9.8

This CVE describes a critical SQL injection vulnerability in the Simple Payroll System with Dynamic Tax Bracket PHP application that allows attackers ...

Oct 22, 2021
CVE-2021-42325
9.8

CVE-2021-42325 is a SQL injection vulnerability in Froxlor's database management component that allows attackers to execute arbitrary SQL commands via...

Oct 12, 2021
CVE-2021-40618
9.8

This SQL injection vulnerability in openSIS Classic 8.0 allows attackers to execute arbitrary SQL commands through specific parameters in HoldAddressF...

Oct 12, 2021
CVE-2021-40543
9.8

This vulnerability allows attackers to execute arbitrary SQL commands on Opensis-Classic Version 8.0 by injecting malicious input into the 'usrid' and...

Oct 11, 2021
CVE-2020-21725
9.8

OpenSNS v6.1.0 contains a blind SQL injection vulnerability in the ChinaCityController component via the pid parameter. This allows attackers to execu...

Oct 7, 2021
CVE-2021-29798
9.8

This SQL injection vulnerability in IBM Sterling B2B Integrator allows remote attackers to execute arbitrary SQL commands against the backend database...

Oct 6, 2021
CVE-2021-29903
9.8

CVE-2021-29903 is a SQL injection vulnerability in IBM Sterling B2B Integrator Standard Edition that allows remote attackers to execute arbitrary SQL ...

Oct 6, 2021
CVE-2021-41511
9.8

This CVE describes an SQL injection vulnerability in the Lodging Reservation Management System V1 login functionality. Attackers can bypass authentica...

Oct 4, 2021
CVE-2020-21012
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands via the email parameter in Hotel and Lodge Management System 2.0...

Oct 1, 2021
CVE-2021-41649
9.8

CVE-2021-41649 is an unauthenticated SQL injection vulnerability in PuneethReddyHC's online-shopping-system-advanced through the /homeaction.php cat_i...

Oct 1, 2021
CVE-2020-20796
9.8

FlameCMS 3.3.5 contains a SQL injection vulnerability in the /master/article.php endpoint via the 'Id' parameter. This allows attackers to execute arb...

Sep 30, 2021
CVE-2021-41288
9.8

CVE-2021-41288 is a critical SQL injection vulnerability in Zoho ManageEngine OpManager's getReportData API. Attackers can execute arbitrary SQL comma...

Sep 30, 2021
CVE-2020-20120
9.8

This CVE describes a SQL injection vulnerability in ThinkPHP v3.2.3 and earlier versions. Attackers can exploit improper input validation in the 'wher...

Sep 28, 2021
CVE-2021-38303
9.8

This SQL injection vulnerability in Sureline SUREedge Migrator allows attackers to execute arbitrary SQL commands on the database. It affects organiza...

Sep 28, 2021
CVE-2021-24666
9.8

This CVE describes a SQL injection vulnerability in the Podlove Podcast Publisher WordPress plugin's 'Social & Donations' module. Attackers can exploi...

Sep 27, 2021
CVE-2021-40674
9.8

This SQL injection vulnerability in Wuzhi CMS v4.1.0 allows attackers to execute arbitrary SQL commands via the KeyValue parameter in the order admini...

Sep 20, 2021
CVE-2021-24741
9.8

The Support Board WordPress plugin before version 3.3.4 contains multiple SQL injection vulnerabilities in POST parameters that are not properly escap...

Sep 20, 2021
CVE-2021-40669
9.8

This SQL injection vulnerability in Wuzhi CMS 4.1.0 allows attackers to execute arbitrary SQL commands through the keywords parameter in the admin int...

Sep 16, 2021
CVE-2020-21127
9.8

MetInfo 7.0.0 contains a SQL injection vulnerability in the admin logs deletion function that allows attackers to execute arbitrary SQL commands. This...

Sep 15, 2021
CVE-2020-21121
9.8

CVE-2020-21121 is a critical SQL injection vulnerability in Pligg CMS that allows attackers to execute arbitrary SQL commands through the admin_update...

Sep 15, 2021
CVE-2021-38833
9.8

This CVE describes a SQL injection vulnerability in PHPGurukul Apartment Visitors Management System v1.0 that allows attackers to execute arbitrary SQ...

Sep 13, 2021
CVE-2021-38727
9.8

CVE-2021-38727 is a SQL injection vulnerability in FUEL CMS that allows attackers to execute arbitrary SQL commands via the 'col' parameter in the log...

Sep 9, 2021
CVE-2021-40814
9.8

This SQL injection vulnerability in the Customer Photo Gallery addon for PrestaShop allows attackers to execute arbitrary SQL commands through the vul...

Sep 8, 2021
CVE-2020-19853
9.8

BlueCMS v1.6 contains a SQL injection vulnerability in the /ad_js.php endpoint that allows attackers to execute arbitrary SQL commands. This affects a...

Sep 8, 2021
CVE-2021-38840
9.8

This vulnerability allows attackers to execute arbitrary SQL commands via the username parameter in the login system of Simple Water Refilling Station...

Sep 7, 2021
CVE-2021-39377
9.8

This SQL injection vulnerability in openSIS 8.0 allows attackers to execute arbitrary SQL commands through the username parameter in index.php when us...

Sep 1, 2021
CVE-2021-39379
9.8

This SQL injection vulnerability in openSIS 8.0 allows attackers to execute arbitrary SQL commands on the MySQL/MariaDB database through the password_...

Sep 1, 2021
CVE-2021-40353
9.8

This is a critical SQL injection vulnerability in openSIS version 8.0 when using MySQL or MariaDB databases. Attackers can inject malicious SQL comman...

Sep 1, 2021
CVE-2021-38145
9.8

This SQL injection vulnerability in Form Tools allows low-privileged client users to execute arbitrary SQL commands via the export_group_id parameter....

Aug 31, 2021
CVE-2021-32983
9.8

A blind SQL injection vulnerability in Delta Electronics DIAEnergie allows remote unauthenticated attackers to execute arbitrary SQL commands. This ca...

Aug 30, 2021
CVE-2021-38390
9.8

A blind SQL injection vulnerability in Delta Electronics DIAEnergie allows remote, unauthenticated attackers to execute arbitrary SQL commands. This c...

Aug 30, 2021
CVE-2021-38393
9.8

A blind SQL injection vulnerability in Delta Electronics DIAEnergie allows remote, unauthenticated attackers to execute arbitrary SQL commands. This c...

Aug 30, 2021
CVE-2021-37749
9.8

CVE-2021-37749 is a blind SQL injection vulnerability in Hexagon GeoMedia WebMap 2020 that allows attackers to execute arbitrary SQL commands via the ...

Aug 30, 2021
CVE-2020-18106
9.8

CVE-2020-18106 is a critical SQL injection vulnerability in WMS v1.0 where the 'id' GET parameter is not properly filtered. This allows attackers to e...

Aug 27, 2021
CVE-2020-20675
9.8

Nuishop v2.3 contains a SQL injection vulnerability in the /goods/getGoodsListByConditions/ endpoint that allows attackers to execute arbitrary SQL co...

Aug 26, 2021
CVE-2020-19705
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the message submission functionality in thinkphp-zcms. It affects all sy...

Aug 26, 2021
CVE-2021-24551
9.8

This SQL injection vulnerability in the Edit Comments WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It affects ...

Aug 23, 2021
CVE-2021-39302
9.8

This vulnerability allows SQL injection in MISP (Malware Information Sharing Platform) through the Log.php component. Attackers can execute arbitrary ...

Aug 19, 2021
CVE-2021-37358
9.8

This is a critical SQL injection vulnerability in SEACMS v210530 that allows remote attackers to execute arbitrary SQL commands via the admin_ajax.php...

Aug 18, 2021

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,802 CVEs classified as CWE-89, with 2,140 rated critical and 2,010 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free