CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,450
Total CVEs
1,899
Critical
1,900
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
241
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Oretnom23 125
2 Phpgurukul 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,450)

CVE-2025-60307
9.8

CVE-2025-60307 is a critical SQL injection vulnerability in code-projects Computer Laboratory System 1.0 that allows authentication bypass via a unive...

Oct 10, 2025
CVE-2025-10586
9.8

This SQL injection vulnerability in the WordPress Community Events plugin allows authenticated attackers with Subscriber-level access or higher to inj...

Oct 9, 2025
CVE-2025-10587
9.8

This SQL injection vulnerability in the WordPress Community Events plugin allows authenticated attackers with Subscriber-level access or higher to inj...

Oct 8, 2025
CVE-2025-52021
9.8

This SQL injection vulnerability in PuneethReddyHC Online Shopping System Advanced 1.0 allows attackers to execute arbitrary SQL commands through the ...

Oct 7, 2025
CVE-2025-0603
9.8

This SQL injection vulnerability in Callvision Healthcare's Callvision Emergency Code software allows attackers to execute arbitrary SQL commands agai...

Oct 7, 2025
CVE-2025-57515
9.8

A critical SQL injection vulnerability in Uniclare Student Portal v2 allows remote attackers to execute arbitrary SQL commands through vulnerable inpu...

Oct 6, 2025
CVE-2025-61605
9.8

WeGIA versions 3.4.12 and below contain an SQL injection vulnerability in the /pet/profile_pet.php endpoint via the id_pet parameter. This allows atta...

Oct 2, 2025
CVE-2025-61603
9.8

CVE-2025-61603 is a critical SQL injection vulnerability in WeGIA web management software for charitable institutions. Attackers can execute arbitrary...

Oct 2, 2025
CVE-2025-59742
9.8

This SQL injection vulnerability in AndSoft's e-TMS v25.03 allows attackers to execute arbitrary SQL commands via the USRMAIL parameter in login forms...

Oct 2, 2025
CVE-2025-59743
9.8

A critical SQL injection vulnerability in AndSoft's e-TMS v25.03 allows attackers to manipulate database operations by exploiting the 'SessionID' cook...

Oct 2, 2025
CVE-2024-13150
9.8

This SQL injection vulnerability in Fayton Software's fayton.Pro ERP allows attackers to execute arbitrary SQL commands through the application. All u...

Sep 29, 2025
CVE-2025-8868
EPSS 14.1% 9.8

An authenticated attacker can exploit SQL injection in Chef Automate's compliance service to gain unauthorized access to restricted functionality. Thi...

Sep 29, 2025
CVE-2025-27261
9.8

Ericsson Indoor Connect 8855 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands on the database. This can...

Sep 25, 2025
CVE-2025-56074
9.8

A SQL injection vulnerability in PHPGurukul Park Ticketing Management System v2.0 allows remote attackers to execute arbitrary SQL commands via the fr...

Sep 22, 2025
CVE-2025-59431
9.8

MapServer versions before 8.4.1 contain a SQL injection vulnerability in the XML Filter Query directive PropertyName. Attackers can bypass expression ...

Sep 19, 2025
CVE-2025-10439
9.8

This SQL injection vulnerability in Yordam Library Automation System allows attackers to execute arbitrary SQL commands through the application. It af...

Sep 17, 2025
CVE-2025-57631
9.8

A critical SQL injection vulnerability in TDuckCloud v5.1 allows remote attackers to execute arbitrary SQL commands via the file upload module. This c...

Sep 16, 2025
CVE-2024-13149
9.8

This SQL injection vulnerability in Arma Store Armalife allows attackers to execute arbitrary SQL commands on the database. It affects all Armalife ve...

Sep 16, 2025
CVE-2025-4688
9.8

This SQL injection vulnerability in BGS Interactive SINAV.LINK Exam Result Module allows attackers to execute arbitrary SQL commands on the database. ...

Sep 16, 2025
CVE-2025-40690
9.8

This SQL injection vulnerability in Online Fire Reporting System v1.2 allows attackers to manipulate the 'teamid' parameter in '/ofrs/admin/edit-team....

Sep 11, 2025
CVE-2025-40692
9.8

This SQL injection vulnerability in Online Fire Reporting System v1.2 allows attackers to manipulate database queries through the 'requestid' paramete...

Sep 11, 2025
CVE-2025-40687
9.8

This SQL injection vulnerability in Online Fire Reporting System v1.2 allows attackers to manipulate database queries through the 'mobilenumber', 'tea...

Sep 11, 2025
CVE-2025-41032
9.8

An SQL injection vulnerability in appRain CMF 4.0.5 allows attackers to manipulate database queries through the 'data[Admin][username]' parameter in t...

Sep 4, 2025
CVE-2025-41034
9.8

An SQL injection vulnerability in appRain CMF 4.0.5 allows attackers to manipulate database queries through the 'data[Page][name]' parameter. This ena...

Sep 4, 2025
CVE-2025-57140
9.8

CVE-2025-57140 is a critical SQL injection vulnerability in rsbi-pom 4.7 that allows attackers to execute arbitrary SQL commands through the /bi/servi...

Sep 2, 2025
CVE-2025-54946
9.8

A SQL injection vulnerability in SUNNET Corporate Training Management System allows remote attackers to execute arbitrary SQL commands. This could lea...

Aug 30, 2025
CVE-2025-44033
9.8

This SQL injection vulnerability in oa_system oasys v1.1 allows remote attackers to execute arbitrary SQL commands via the allDirector() method. Attac...

Aug 29, 2025
CVE-2025-57819
KEV EPSS 74.2% 9.8

CVE-2025-57819 is a critical vulnerability in FreePBX that allows unauthenticated attackers to bypass authentication, gain administrator access, manip...

Aug 28, 2025
CVE-2024-13979
9.8

This is a critical SQL injection vulnerability in the St. Joe ERP system that allows unauthenticated remote attackers to execute arbitrary SQL command...

Aug 27, 2025
CVE-2025-50972
9.8

CVE-2025-50972 is a critical SQL injection vulnerability in AbanteCart e-commerce software that allows unauthenticated attackers to execute arbitrary ...

Aug 27, 2025
CVE-2025-55575
9.8

CVE-2025-55575 is a critical SQL injection vulnerability in SMM Panel 3.1 that allows remote attackers to execute arbitrary SQL commands via crafted H...

Aug 25, 2025
CVE-2025-56212
9.8

CVE-2025-56212 is a critical SQL injection vulnerability in phpgurukul Hospital Management System 4.0 that allows attackers to execute arbitrary SQL c...

Aug 25, 2025
CVE-2025-51092
9.8

This SQL injection vulnerability in the LogIn-SignUp PHP project allows attackers to execute arbitrary SQL commands by manipulating login or registrat...

Aug 22, 2025
CVE-2025-55168
9.8

This SQL injection vulnerability in WeGIA allows attackers to execute arbitrary SQL commands through the id_fichamedica parameter in the /html/saude/a...

Aug 12, 2025
CVE-2025-55167
9.8

CVE-2025-55167 is a critical SQL injection vulnerability in WeGIA web management software that allows attackers to execute arbitrary SQL commands thro...

Aug 12, 2025
CVE-2024-32640
EPSS 93.7% 9.8

CVE-2024-32640 is a critical SQL injection vulnerability in MASA CMS that allows attackers to execute arbitrary SQL commands through the processAsyncO...

Aug 11, 2025
CVE-2023-41525
9.8

Hospital Management System v4 contains a SQL injection vulnerability in the patient_contact parameter of patientsearch.php. This allows attackers to e...

Aug 7, 2025
CVE-2023-41527
9.8

This SQL injection vulnerability in Hospital Management System v4 allows attackers to execute arbitrary SQL commands through the password2 parameter. ...

Aug 7, 2025
CVE-2023-41530
9.8

This SQL injection vulnerability in Hospital Management System v4 allows attackers to execute arbitrary SQL commands through the app_contact parameter...

Aug 7, 2025
CVE-2025-50341
9.8

A Boolean-based SQL injection vulnerability in Axelor 5.2.4 allows attackers to manipulate SQL queries via the _domain parameter. This enables data ex...

Aug 4, 2025
CVE-2025-41375
9.8

A SQL injection vulnerability in LimeSurvey v2.65.1+170522 allows attackers to manipulate database queries via the 'token' parameter in the '/index.ph...

Aug 1, 2025
CVE-2025-40682
9.8

This SQL injection vulnerability in Human Resource Management System version 1.0 allows attackers to manipulate database queries through the 'city' an...

Jul 29, 2025
CVE-2025-6918
9.8

This SQL injection vulnerability in Ncvav Virtual PBX Software allows attackers to execute arbitrary SQL commands through the application. All systems...

Jul 28, 2025
CVE-2025-32429
EPSS 38.1% 9.8

This CVE describes a critical SQL injection vulnerability in XWiki Platform that allows unauthenticated attackers to execute arbitrary SQL commands vi...

Jul 24, 2025
CVE-2025-54379
9.8

CVE-2025-54379 is a critical SQL injection vulnerability in LF Edge eKuiper's getLast API that allows unauthenticated remote attackers to execute arbi...

Jul 24, 2025
CVE-2025-4784
9.8

This SQL injection vulnerability in Moderec Tourtella allows attackers to execute arbitrary SQL commands through unvalidated user input. It affects al...

Jul 24, 2025
CVE-2025-4822
9.8

This SQL injection vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows attackers to execute arbitrary SQL commands on the database. It...

Jul 24, 2025
CVE-2025-7624
9.8

An SQL injection vulnerability in Sophos Firewall's legacy SMTP proxy allows remote attackers to execute arbitrary code on affected systems. This affe...

Jul 21, 2025
CVE-2025-7343
9.8

This SQL injection vulnerability in Digiwin's SFT software allows unauthenticated remote attackers to execute arbitrary SQL commands against the datab...

Jul 21, 2025
CVE-2025-7918
9.8

CVE-2025-7918 is a critical SQL injection vulnerability in WinMatrix3 Web package that allows unauthenticated remote attackers to execute arbitrary SQ...

Jul 21, 2025

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,450 CVEs classified as CWE-89, with 1,899 rated critical and 1,900 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free