CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,819
Total CVEs
2,152
Critical
2,015
High
8.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
247
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 131
2 Oretnom23 125
3 Projectworlds 53
4 Code Projects 50
5 Siemens 47
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Ivanti 37
10 Mayurik 37

All SQL Injection CVEs (4,819)

CVE-2020-22210
9.8

CVE-2020-22210 is a critical SQL injection vulnerability in 74cms version 3.2.0 that allows attackers to execute arbitrary SQL commands via the x para...

Jun 16, 2021
CVE-2020-22212
9.8

This is a critical SQL injection vulnerability in 74cms version 3.2.0 that allows attackers to execute arbitrary SQL commands via the 'id' parameter i...

Jun 16, 2021
CVE-2020-22199
9.8

This CVE describes a SQL injection vulnerability in phpCMS 2007 that allows attackers to execute arbitrary SQL commands through the digg_mod parameter...

Jun 16, 2021
CVE-2020-22198
9.8

This CVE describes a SQL injection vulnerability in DedeCMS 5.7 that allows attackers to execute arbitrary SQL commands via the mdescription parameter...

Jun 16, 2021
CVE-2020-35441
9.8

CVE-2020-35441 is a critical SQL injection vulnerability in FDCMS (Fangfa Content Management System) 4.0 that allows attackers to execute arbitrary SQ...

Jun 2, 2021
CVE-2021-24321
9.8

This vulnerability allows SQL injection attacks in the Bello WordPress theme before version 1.6.0. Attackers can exploit unsanitized parameters to exe...

Jun 1, 2021
CVE-2021-33470
9.8

COVID19 Testing Management System 1.0 contains a SQL injection vulnerability in the admin panel that allows attackers to execute arbitrary SQL command...

May 26, 2021
CVE-2019-12348
9.8

This SQL injection vulnerability in zzcms 2019 allows attackers to execute arbitrary SQL commands through the daohang or img POST parameters in user/z...

May 24, 2021
CVE-2020-25409
9.8

CVE-2020-25409 is a critical SQL injection vulnerability in Projectsworlds College Management System PHP 1.0 that allows attackers to execute arbitrar...

May 24, 2021
CVE-2021-20720
9.8

CVE-2021-20720 is a critical SQL injection vulnerability in KonaWiki2 that allows remote attackers to execute arbitrary SQL commands. This enables att...

May 20, 2021
CVE-2021-31316
9.8

This SQL injection vulnerability in CentOS Web Panel's unprivileged user portal allows attackers to execute arbitrary SQL commands via the 'idsession'...

May 18, 2021
CVE-2021-32615
9.8

This vulnerability allows authenticated administrators in Piwigo 11.4.0 to perform SQL injection attacks via the order[0][dir] parameter in admin/user...

May 13, 2021
CVE-2021-32099
9.8

An unauthenticated SQL injection vulnerability in Pandora FMS allows attackers to bypass authentication by manipulating session parameters. This affec...

May 7, 2021
CVE-2020-19108
9.8

CVE-2020-19108 is a critical SQL injection vulnerability in Online Book Store v1.0 that allows remote attackers to execute arbitrary SQL commands thro...

May 6, 2021
CVE-2020-19110
9.8

This CVE describes a SQL injection vulnerability in Online Book Store v1.0, allowing remote attackers to execute arbitrary SQL commands via the bookis...

May 6, 2021
CVE-2020-19114
9.8

This CVE describes a SQL injection vulnerability in Online Book Store v1.0 that allows remote attackers to execute arbitrary SQL commands via the publ...

May 6, 2021
CVE-2020-19107
9.8

This CVE describes a SQL injection vulnerability in Online Book Store v1.0 that allows attackers to execute arbitrary SQL commands through the isbn pa...

May 6, 2021
CVE-2020-22807
9.8

CVE-2020-22807 is a critical SQL injection vulnerability in vtiger CRM's calendar export feature that allows attackers to execute arbitrary SQL comman...

Apr 29, 2021
CVE-2020-18020
9.8

CVE-2020-18020 is a critical SQL injection vulnerability in PHPSHE Mall System v1.7 that allows remote attackers to execute arbitrary SQL commands via...

Apr 28, 2021
CVE-2020-27240
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on OpenClinic GA systems through the componentStatus parameter i...

Apr 19, 2021
CVE-2020-27237
9.8

This vulnerability allows unauthenticated SQL injection attacks against OpenClinic GA's getAssets.jsp page via the nomenclature parameter. Attackers c...

Apr 15, 2021
CVE-2020-27239
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on OpenClinic GA systems via the assetStatus parameter in getAss...

Apr 15, 2021
CVE-2021-30459
9.8

This SQL injection vulnerability in Django Debug Toolbar allows attackers to execute arbitrary SQL statements by manipulating the raw_sql input field ...

Apr 14, 2021
CVE-2021-27130
9.8

CVE-2021-27130 is a critical SQL injection vulnerability in Online Reviewer System 1.0 that allows authentication bypass and remote code execution. At...

Apr 14, 2021
CVE-2020-27235
9.8

This is an authenticated SQL injection vulnerability in OpenClinic GA's 'getAssets.jsp' page that allows attackers to execute arbitrary SQL commands t...

Apr 13, 2021
CVE-2020-27233
9.8

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the supplierUID parameter in OpenClinic GA's getAssets.jsp...

Apr 13, 2021
CVE-2021-30175
9.8

ZEROF Web Server 1.0 (April 2021) contains a SQL injection vulnerability in the /HandleEvent endpoint used for login authentication. This allows attac...

Apr 13, 2021
CVE-2020-23763
9.8

This vulnerability allows remote attackers to execute arbitrary SQL commands via the admin.php file in Online Book Store 1.0, leading to authenticatio...

Apr 9, 2021
CVE-2021-28925
9.8

This SQL injection vulnerability in Nagios Network Analyzer allows attackers to execute arbitrary SQL commands via the o[col] parameter in the api/che...

Apr 8, 2021
CVE-2021-30000
9.8

This vulnerability allows SQL injection through the txtaccesscode parameter in LATRIX 0.6.0's inandout.php file, enabling attackers to extract databas...

Apr 2, 2021
CVE-2020-28172
9.8

CVE-2020-28172 is a critical SQL injection vulnerability in Simple College Website 1.0 that allows unauthenticated attackers to bypass admin authentic...

Mar 31, 2021
CVE-2020-10582
9.8

This vulnerability allows remote attackers to execute arbitrary SQL commands through the /admin/display_errors.php script in Invigo ADM. Attackers can...

Mar 25, 2021
CVE-2020-35337
9.8

CVE-2020-35337 is a SQL injection vulnerability in ThinkSAAS CMS that allows authenticated attackers to execute arbitrary SQL commands via the title p...

Mar 24, 2021
CVE-2020-6577
9.8

This vulnerability allows SQL injection through the IT-Recht Kanzlei plugin in Zen Cart's German edition. Attackers can execute arbitrary SQL commands...

Mar 19, 2021
CVE-2021-24139
9.8

This vulnerability allows attackers to execute arbitrary SQL commands on WordPress sites using the Photo Gallery plugin. It affects all WordPress inst...

Mar 18, 2021
CVE-2021-22859
9.8

This is a critical SQL injection vulnerability in the EIC e-document system's user data querying function. Attackers can execute arbitrary SQL command...

Mar 17, 2021
CVE-2021-28381
9.8

This vulnerability allows SQL injection in the vhs (VHS: Fluid ViewHelpers) extension for TYPO3 through the isLanguageViewHelper component. Attackers ...

Mar 16, 2021
CVE-2020-24877
9.8

This SQL injection vulnerability in zzzphp v1.8.0 allows attackers to execute arbitrary SQL commands through the /form/index.php?module=getjson endpoi...

Mar 15, 2021
CVE-2020-24791
9.8

This vulnerability allows SQL injection in FUEL CMS 1.4.8 through the 'fuel_replace_id' parameter. Attackers can execute arbitrary SQL commands, poten...

Mar 10, 2021
CVE-2021-27581
9.8

This SQL injection vulnerability in Kentico CMS allows attackers to execute arbitrary SQL commands via the tagname parameter in the Blog module. It af...

Mar 5, 2021
CVE-2021-27314
9.8

CVE-2021-27314 is a critical SQL injection vulnerability in Doctor Appointment System 1.0 that allows unauthenticated attackers to execute arbitrary S...

Mar 5, 2021
CVE-2020-24913
9.8

CVE-2020-24913 is a critical SQL injection vulnerability in QCubed PHP framework's profile.php file. Unauthenticated attackers can execute arbitrary S...

Mar 4, 2021
CVE-2020-28657
9.8

CVE-2020-28657 is a critical SQL injection vulnerability in bPanel 2.0 that allows unauthenticated attackers to execute arbitrary SQL commands through...

Mar 2, 2021
CVE-2021-26904
9.8

CVE-2021-26904 is a critical SQL injection vulnerability in LMA ISIDA Retriever 5.2 that allows attackers to execute arbitrary SQL commands on the dat...

Feb 26, 2021
CVE-2021-25779
9.8

Baby Care System v1.0 contains a SQL injection vulnerability in the 'id' parameter of contentsectionpage.php. This allows attackers to execute arbitra...

Feb 17, 2021
CVE-2021-27234
9.8

This SQL injection vulnerability in Mutare Voice (EVM) allows attackers to execute arbitrary SQL commands on the web application through multiple ASP ...

Feb 16, 2021
CVE-2021-26200
9.8

CVE-2021-26200 is an SQL injection vulnerability in Library System 1.0 that allows attackers to bypass authentication and gain admin privileges. This ...

Feb 15, 2021
CVE-2021-26822
9.8

CVE-2021-26822 is a critical SQL injection vulnerability in Teachers Record Management System 1.0 that allows remote unauthenticated attackers to exec...

Feb 15, 2021
CVE-2019-25019
9.8

This SQL injection vulnerability in LimeSurvey's participant model allows attackers to execute arbitrary SQL commands on the database. It affects all ...

Feb 14, 2021
CVE-2021-22658
9.8

CVE-2021-22658 is a SQL injection vulnerability in Advantech iView software that allows attackers to execute arbitrary SQL commands. Successful exploi...

Feb 11, 2021

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,819 CVEs classified as CWE-89, with 2,152 rated critical and 2,015 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.5.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free