CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,804
Total CVEs
2,140
Critical
2,012
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
246
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 131
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,804)

CVE-2020-18164
9.8

This CVE describes a SQL injection vulnerability in tp-shop e-commerce software that allows attackers to execute arbitrary SQL commands through the fB...

Aug 17, 2021
CVE-2021-36789
9.8

This vulnerability allows SQL injection in the dated_news extension for TYPO3, enabling attackers to execute arbitrary SQL commands on the database. I...

Aug 13, 2021
CVE-2021-38302
9.8

This vulnerability allows SQL injection in the Newsletter extension for TYPO3 CMS. Attackers can execute arbitrary SQL commands through the extension'...

Aug 13, 2021
CVE-2021-37350
9.8

CVE-2021-37350 is a critical SQL injection vulnerability in Nagios XI's Bulk Modifications Tool that allows attackers to execute arbitrary SQL command...

Aug 13, 2021
CVE-2021-28890
9.8

CVE-2021-28890 is a critical SQL injection vulnerability in J2eeFAST that allows remote attackers to execute arbitrary SQL commands via specific param...

Aug 12, 2021
CVE-2020-20975
9.8

This is a SQL injection vulnerability in Gxlcms v1.1 that allows attackers to execute arbitrary SQL commands via the $filename parameter in the dataac...

Aug 12, 2021
CVE-2021-38574
9.8

This vulnerability allows SQL injection attacks in Foxit Reader and PhantomPDF through crafted data appended to strings. Attackers can execute arbitra...

Aug 11, 2021
CVE-2021-24507
9.8

This vulnerability allows attackers to execute arbitrary SQL commands on WordPress sites using the Astra Pro Addon plugin. Both unauthenticated and au...

Aug 9, 2021
CVE-2021-38167
9.8

CVE-2021-38167 is a SQL injection vulnerability in Roxy-WI's check_login function that allows unauthenticated attackers to extract valid UUIDs and byp...

Aug 7, 2021
CVE-2021-38159
9.8

CVE-2021-38159 is a critical SQL injection vulnerability in Progress MOVEit Transfer that allows unauthenticated remote attackers to execute arbitrary...

Aug 7, 2021
CVE-2021-20028
9.8

This CVE describes a critical SQL injection vulnerability in SonicWall Secure Remote Access (SRA) appliances. Attackers can exploit this to execute ar...

Aug 4, 2021
CVE-2021-37558
9.8

This is a critical SQL injection vulnerability in Centreon's MediaWiki integration that allows remote unauthenticated attackers to execute arbitrary S...

Aug 3, 2021
CVE-2021-37832
9.8

CVE-2021-37832 is a critical SQL injection vulnerability in Hotel Druid 3.0.2 when using SQLite database. Attackers can execute arbitrary SQL commands...

Aug 3, 2021
CVE-2021-36624
9.8

CVE-2021-36624 is a critical SQL injection vulnerability in Phone Shop Sales Management System version 1.0 that allows attackers to bypass authenticat...

Jul 30, 2021
CVE-2021-34165
9.8

This SQL injection vulnerability in Basic Shopping Cart 1.0 allows remote attackers to bypass authentication and gain administrative privileges by man...

Jul 30, 2021
CVE-2021-35458
9.8

Online Pet Shop We App 1.0 contains a critical SQL injection vulnerability in the products.php page via the 'c' or 's' parameters. This allows attacke...

Jul 30, 2021
CVE-2020-18013
9.8

This is a critical SQL injection vulnerability in Whatsns 4.0 that allows attackers to execute arbitrary SQL commands via the ip parameter in the admi...

Jul 30, 2021
CVE-2020-18175
9.8

This CVE describes a SQL injection vulnerability in Metinfo CMS version 6.1.3 that allows attackers to execute arbitrary SQL commands via the dosafety...

Jul 30, 2021
CVE-2020-21806
9.8

CVE-2020-21806 is a critical SQL injection vulnerability in ECTouch v2 e-commerce software that allows attackers to execute arbitrary SQL commands thr...

Jul 30, 2021
CVE-2020-21809
9.8

CVE-2020-21809 is a critical SQL injection vulnerability in NukeViet CMS's Shops module that allows attackers to execute arbitrary SQL commands throug...

Jul 30, 2021
CVE-2021-37473
9.8

This SQL injection vulnerability in NavigateCMS allows attackers to execute arbitrary SQL queries through the 'products-order' parameter in product.ph...

Jul 26, 2021
CVE-2021-37476
9.8

This SQL injection vulnerability in NavigateCMS allows attackers to execute arbitrary SQL queries through the 'id' parameter in product.php. Attackers...

Jul 26, 2021
CVE-2021-37478
9.8

CVE-2021-37478 is a SQL injection vulnerability in NavigateCMS that allows attackers to execute arbitrary SQL queries through the 'block-order' parame...

Jul 26, 2021
CVE-2021-25205
9.8

CVE-2021-25205 is a critical SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 that allows remote attackers to execute arbitrary ...

Jul 22, 2021
CVE-2021-26223
9.8

CVE-2021-26223 is a critical SQL injection vulnerability in CASAP Automated Enrollment System v1.0 that allows remote attackers to execute arbitrary S...

Jul 22, 2021
CVE-2021-25202
9.8

This CVE describes a SQL injection vulnerability in the SourceCodester Sales and Inventory System v1.0 that allows remote attackers to execute arbitra...

Jul 22, 2021
CVE-2020-36033
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the id parameter in edituser.php in Water Billing System 1.0. This can l...

Jul 22, 2021
CVE-2021-26228
9.8

CVE-2021-26228 is a critical SQL injection vulnerability in CASAP Automated Enrollment System v1.0 that allows remote attackers to execute arbitrary S...

Jul 22, 2021
CVE-2021-26231
9.8

CVE-2021-26231 is a critical SQL injection vulnerability in Fantastic Blog CMS v1.0 that allows remote attackers to execute arbitrary SQL commands via...

Jul 22, 2021
CVE-2021-26765
9.8

CVE-2021-26765 is a critical SQL injection vulnerability in PHPGurukul Student Record System 4.0 that allows remote attackers to execute arbitrary SQL...

Jul 22, 2021
CVE-2020-35427
9.8

CVE-2020-35427 is a critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 that allows remote attackers to execute a...

Jul 20, 2021
CVE-2020-18155
9.8

This CVE describes a SQL injection vulnerability in Subrion CMS v4.2.1 that occurs in the search page when the website uses a PDO connection. Attacker...

Jul 14, 2021
CVE-2020-18144
9.8

CVE-2020-18144 is a critical SQL injection vulnerability in ECTouch v2 e-commerce software that allows attackers to execute arbitrary SQL commands via...

Jul 14, 2021
CVE-2021-33578
9.8

CVE-2021-33578 is a critical SQL injection vulnerability in Echo ShareCare 8.15.5 that allows both authenticated and unauthenticated attackers to exec...

Jul 13, 2021
CVE-2021-24442
9.8

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites using the WPDevArt Polls plugin. Attackers can...

Jul 12, 2021
CVE-2020-18544
9.8

CVE-2020-18544 is a critical SQL injection vulnerability in WMS v1.0 that allows remote attackers to execute arbitrary SQL commands via the username p...

Jul 12, 2021
CVE-2021-24385
9.8

CVE-2021-24385 is a critical SQL injection vulnerability in the FileBird WordPress plugin that allows unauthenticated attackers to execute arbitrary S...

Jul 12, 2021
CVE-2020-21132
9.8

This is a critical SQL injection vulnerability in Metinfo 7.0.0beta that allows attackers to execute arbitrary SQL commands through the index.php file...

Jul 12, 2021
CVE-2021-24007
9.8

This CVE describes SQL injection vulnerabilities in FortiMail email security appliances that allow unauthenticated attackers to execute arbitrary SQL ...

Jul 9, 2021
CVE-2021-35042
9.8

This vulnerability allows SQL injection in Django applications when untrusted user input is passed to QuerySet.order_by() methods. Attackers can execu...

Jul 2, 2021
CVE-2020-23711
9.8

NavigateCMS 2.9 contains a SQL injection vulnerability in the navigate.php file via the URL-encoded GET parameter 'category'. This allows attackers to...

Jun 28, 2021
CVE-2021-34187
9.8

This SQL injection vulnerability in Chamilo LMS allows attackers to execute arbitrary SQL commands via the searchField, filters, or filters2 parameter...

Jun 28, 2021
CVE-2021-35456
9.8

Online Pet Shop We App 1.0 contains SQL injection and shell upload vulnerabilities that allow attackers to execute arbitrary SQL commands and upload m...

Jun 28, 2021
CVE-2020-18662
9.8

This CVE describes a SQL injection vulnerability in gnuboard5's installation script that allows attackers to execute arbitrary SQL commands via the ta...

Jun 24, 2021
CVE-2020-20392
9.8

This CVE describes a critical SQL injection vulnerability in imcat v5.2 that allows attackers to execute arbitrary SQL commands through the fm[auser] ...

Jun 23, 2021
CVE-2021-24361
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Location Manager plugin before vers...

Jun 21, 2021
CVE-2021-3604
9.8

CVE-2021-3604 is a critical SQL injection vulnerability in Primion Digitek Secure 8 (Evalos) that allows remote attackers to extract sensitive user an...

Jun 18, 2021
CVE-2020-22203
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the genre parameter in phpCMS 2008 sp4's yp/job.php file. This affects a...

Jun 16, 2021
CVE-2020-22205
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the id parameter in ECShop 3.0's admin/shophelp.php file. This affects a...

Jun 16, 2021
CVE-2020-22208
9.8

This vulnerability allows attackers to execute arbitrary SQL commands via the x parameter in plus/ajax_street.php in 74cms version 3.2.0. It affects a...

Jun 16, 2021

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,804 CVEs classified as CWE-89, with 2,140 rated critical and 2,012 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free