CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,461
Total CVEs
1,908
Critical
1,902
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
241
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Oretnom23 125
2 Phpgurukul 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,461)

CVE-2025-7918
9.8

CVE-2025-7918 is a critical SQL injection vulnerability in WinMatrix3 Web package that allows unauthenticated remote attackers to execute arbitrary SQ...

Jul 21, 2025
CVE-2025-26854
9.8

This SQL injection vulnerability in the Articles Good Search extension for Joomla allows attackers to execute arbitrary SQL commands on affected syste...

Jul 18, 2025
CVE-2025-50240
9.8

CVE-2025-50240 is a critical SQL injection vulnerability in nbcio-boot v1.0.3 that allows attackers to execute arbitrary SQL commands via the userIds ...

Jul 17, 2025
CVE-2025-25257
KEV EPSS 45.4% 9.8

This SQL injection vulnerability in Fortinet FortiWeb web application firewalls allows unauthenticated attackers to execute arbitrary SQL commands via...

Jul 17, 2025
CVE-2025-53937
9.8

A SQL injection vulnerability in WeGIA's /controle/control.php endpoint allows attackers to execute arbitrary SQL commands via the cargo parameter. Th...

Jul 16, 2025
CVE-2025-53639
9.8

This SQL injection vulnerability in MeterSphere allows attackers to execute arbitrary SQL commands through the sortField parameter in API endpoints. T...

Jul 14, 2025
CVE-2025-40713
9.8

A critical SQL injection vulnerability in Quiter Gateway versions before 4.7.0 allows attackers to manipulate database operations through the campo pa...

Jul 8, 2025
CVE-2025-40715
9.8

A SQL injection vulnerability in Quiter Gateway allows attackers to manipulate database operations through the 'campo mensaje' parameter in the /QISCl...

Jul 8, 2025
CVE-2025-40717
9.8

A critical SQL injection vulnerability in Quiter Gateway versions before 4.7.0 allows attackers to manipulate database queries through the pagina.filt...

Jul 8, 2025
CVE-2025-40711
9.8

A critical SQL injection vulnerability in Quiter Gateway allows attackers to manipulate database operations through the id_concesion parameter. This a...

Jul 8, 2025
CVE-2025-53527
9.8

A time-based blind SQL injection vulnerability exists in the WeGIA web manager for charitable institutions. Attackers can inject arbitrary SQL queries...

Jul 7, 2025
CVE-2025-28983
9.8

This SQL injection vulnerability in ClickandPledge Click & Pledge Connect WordPress plugin allows attackers to execute arbitrary SQL commands, potenti...

Jul 4, 2025
CVE-2025-40731
9.8

A critical SQL injection vulnerability in Daily Expense Manager v1.0 allows attackers to manipulate database operations through unvalidated parameters...

Jun 30, 2025
CVE-2024-12143
9.8

This SQL injection vulnerability in Mobilteg Mobile Informatics Mikro Hand Terminal - MikroDB allows attackers to execute arbitrary SQL commands on th...

Jun 27, 2025
CVE-2024-12364
9.8

This SQL injection vulnerability in Mavi Yeşil Software Guest Tracking Software allows attackers to execute arbitrary SQL commands through unvalidate...

Jun 27, 2025
CVE-2024-11739
9.8

This SQL injection vulnerability in Case Informatics Case ERP allows attackers to execute arbitrary SQL commands through the application. All organiza...

Jun 27, 2025
CVE-2015-0842
9.8

CVE-2015-0842 is a SQL injection vulnerability in yubiserver versions before 0.6 that allows attackers to manipulate database queries. This can lead t...

Jun 26, 2025
CVE-2021-41691
9.8

This SQL injection vulnerability in OS4Ed OpenSIS allows attackers to execute arbitrary SQL commands through manipulated student_id and TRANSFER{SCHOO...

Jun 24, 2025
CVE-2025-46179
9.8

This SQL injection vulnerability in CloudClassroom-PHP v1.0 allows attackers to execute arbitrary SQL commands through the unsanitized squeryx paramet...

Jun 20, 2025
CVE-2025-4738
9.8

This SQL injection vulnerability in Yirmibes Software MY ERP allows attackers to execute arbitrary SQL commands through unvalidated user input. It aff...

Jun 19, 2025
CVE-2025-6169
9.8

CVE-2025-6169 is a critical SQL injection vulnerability in HAMASTAR Technology's WIMP website co-construction management platform that allows unauthen...

Jun 16, 2025
CVE-2024-56158
9.8

This vulnerability allows authenticated XWiki users to execute arbitrary SQL queries on Oracle databases through unsanitized DBMS_XMLGEN and DBMS_XMLQ...

Jun 12, 2025
CVE-2025-40656
9.8

A critical SQL injection vulnerability in DM Corporative CMS allows attackers to manipulate database queries through the 'cod' parameter in /administe...

Jun 10, 2025
CVE-2025-40654
9.8

A critical SQL injection vulnerability in DM Corporative CMS allows attackers to manipulate database queries through the name and cod parameters in /a...

Jun 10, 2025
CVE-2025-1793
9.8

SQL injection vulnerabilities in multiple vector store integrations of run-llama/llama_index v0.12.21 allow attackers to execute arbitrary SQL command...

Jun 5, 2025
CVE-2025-4578
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the File Provider plugin. Attackers can...

Jun 4, 2025
CVE-2025-1750
9.8

An SQL injection vulnerability in DuckDBVectorStore's delete function allows attackers to manipulate the ref_doc_id parameter to execute arbitrary SQL...

Jun 2, 2025
CVE-2025-48949
9.8

CVE-2025-48949 is a critical SQL injection vulnerability in Navidrome music server affecting versions 0.55.0 through 0.55.2. Attackers can exploit imp...

May 30, 2025
CVE-2025-40666
9.8

CVE-2025-40666 is a critical SQL injection vulnerability in TCMAN's GIM v11 that allows attackers to manipulate databases through the ArbolID paramete...

May 26, 2025
CVE-2025-32814
EPSS 22.4% 9.8

Unauthenticated SQL injection vulnerability in Infoblox NETMRI allows attackers to execute arbitrary SQL commands without authentication. This affects...

May 22, 2025
CVE-2024-6809
9.8

CVE-2024-6809 is a critical SQL injection vulnerability in the Simple Video Directory WordPress plugin that allows unauthenticated attackers to execut...

May 15, 2025
CVE-2024-6159
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Push Notification for Post and Budd...

May 15, 2025
CVE-2025-46052
9.8

An error-based SQL injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands by injecting malicious payloads into t...

May 15, 2025
CVE-2025-28056
9.8

CVE-2025-28056 is a critical SQL injection vulnerability in rebuild's admin-cli/exec component that allows attackers to execute arbitrary SQL commands...

May 13, 2025
CVE-2025-44831
9.8

EngineerCMS versions 1.02 through 2.0.5 contain a SQL injection vulnerability in the /project/addproject interface. This allows attackers to execute a...

May 13, 2025
CVE-2023-49641
9.8

Billing Software v1.0 contains unauthenticated SQL injection vulnerabilities in the loginCheck.php file, allowing attackers to execute arbitrary SQL c...

May 13, 2025
CVE-2025-4559
9.8

CVE-2025-4559 is a critical SQL injection vulnerability in Netvision ISOinsight software that allows unauthenticated remote attackers to execute arbit...

May 12, 2025
CVE-2025-46190
9.8

This SQL injection vulnerability in SourceCodester Client Database Management System 1.0 allows attackers to execute arbitrary SQL commands through th...

May 9, 2025
CVE-2025-46192
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the order_id parameter in user_payment_update.php. It affects SourceCode...

May 9, 2025
CVE-2025-46189
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the order_id parameter in the user_order_customer_update.php file of Sou...

May 9, 2025
CVE-2025-46828
9.8

An unauthenticated SQL injection vulnerability in WeGIA versions up to 3.3.0 allows attackers to execute arbitrary SQL commands via the /html/socio/si...

May 7, 2025
CVE-2025-0668
9.8

This CVE describes a stored cross-site scripting (XSS) vulnerability in BOINC Server that allows attackers to inject malicious scripts into web pages....

May 7, 2025
CVE-2025-44073
9.8

SeaCMS v13.3 contains a SQL injection vulnerability in the admin_comment_news.php component that allows attackers to execute arbitrary SQL commands. T...

May 6, 2025
CVE-2025-40624
9.8

An unauthenticated SQL injection vulnerability in TCMAN's GIM v11 allows attackers to execute arbitrary SQL commands through the 'User' and 'email' pa...

May 6, 2025
CVE-2025-40622
9.8

This is a critical SQL injection vulnerability in TCMAN's GIM v11 software that allows unauthenticated attackers to execute arbitrary SQL commands thr...

May 6, 2025
CVE-2025-40620
9.8

This is a critical SQL injection vulnerability in TCMAN's GIM v11 software that allows unauthenticated attackers to execute arbitrary SQL commands thr...

May 6, 2025
CVE-2025-44074
9.8

SeaCMS v13.3 contains a SQL injection vulnerability in the admin_topic.php component that allows attackers to execute arbitrary SQL commands. This aff...

May 5, 2025
CVE-2025-2812
9.8

This CVE describes a blind SQL injection vulnerability in Mydata Informatics Ticket Sales Automation software, allowing attackers to execute arbitrary...

May 2, 2025
CVE-2025-3708
9.8

CVE-2025-3708 is a critical SQL injection vulnerability in Le-show medical practice management system that allows unauthenticated remote attackers to ...

May 2, 2025
CVE-2025-44192
9.8

CVE-2025-44192 is a critical SQL injection vulnerability in Simple Barangay Management System v1.0 that allows attackers to execute arbitrary SQL comm...

Apr 30, 2025

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,461 CVEs classified as CWE-89, with 1,908 rated critical and 1,902 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free