CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,468
Total CVEs
1,913
Critical
1,904
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
241
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 126
2 Oretnom23 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,468)

CVE-2025-45017
9.8

A critical SQL injection vulnerability in PHPGurukul Park Ticketing Management System v2.0 allows remote attackers to execute arbitrary SQL commands v...

Apr 30, 2025
CVE-2025-40617
9.8

A critical SQL injection vulnerability in Bookgy allows attackers to manipulate database operations through unvalidated HTTP parameters. Attackers can...

Apr 29, 2025
CVE-2025-25403
9.8

CVE-2025-25403 is a critical SQL injection vulnerability in Slims 9 Bulian library management system that allows attackers to execute arbitrary SQL co...

Apr 29, 2025
CVE-2025-25775
9.8

This vulnerability allows attackers to execute arbitrary SQL commands via the kodetiket parameter in the Bus Ticket Booking System. Attackers can pote...

Apr 25, 2025
CVE-2025-32969
EPSS 21.2% 9.8

This vulnerability allows remote unauthenticated attackers to perform blind SQL injection on XWiki instances, potentially executing arbitrary SQL stat...

Apr 23, 2025
CVE-2025-28009
9.8

A SQL injection vulnerability in Dietiqa App v1.0.20 allows attackers to execute arbitrary SQL commands via the 'u' parameter in the progress-body-wei...

Apr 17, 2025
CVE-2025-27495
9.8

This critical SQL injection vulnerability in TeleControl Server Basic allows unauthenticated remote attackers to bypass authorization, read/write to t...

Apr 16, 2025
CVE-2025-27540
9.8

An unauthenticated SQL injection vulnerability in TeleControl Server Basic allows remote attackers to bypass authentication, read/write to the databas...

Apr 16, 2025
CVE-2024-40073
9.8

This SQL injection vulnerability in Sourcecodester Online ID Generator System 1.0 allows attackers to execute arbitrary SQL commands via the template ...

Apr 16, 2025
CVE-2025-28100
9.8

A SQL injection vulnerability in dingfanzuCMS v1.0 allows attackers to execute arbitrary SQL commands via the 'id' parameter in operateOrder.php. This...

Apr 15, 2025
CVE-2024-22611
9.8

CVE-2024-22611 is a critical SQL injection vulnerability in OpenEMR that allows attackers to execute arbitrary SQL commands through pharmacy-related c...

Apr 3, 2025
CVE-2025-29369
9.8

CVE-2025-29369 is a critical SQL injection vulnerability in Code-Projects Matrimonial Site V1.0 that allows attackers to execute arbitrary SQL command...

Apr 3, 2025
CVE-2025-22930
9.8

This SQL injection vulnerability in OS4ED openSIS allows attackers to execute arbitrary SQL commands via the groupid parameter in the Group.php messag...

Apr 3, 2025
CVE-2025-29085
EPSS 22.6% 9.8

This CVE describes a critical SQL injection vulnerability in vipshop Saturn's console dashboard component. Remote attackers can execute arbitrary SQL ...

Apr 2, 2025
CVE-2025-3011
9.8

CVE-2025-3011 is a critical SQL injection vulnerability in SOOP-CLM from PiExtract that allows unauthenticated remote attackers to execute arbitrary S...

Mar 31, 2025
CVE-2025-22953
9.8

This is an unauthenticated SQL injection vulnerability in Epicor HCM's JsonFetcher.svc endpoint that allows attackers to execute arbitrary SQL command...

Mar 28, 2025
CVE-2025-30372
9.8

Emlog Pro versions 2.5.7 and 2.5.8 contain an SQL injection vulnerability in search_controller.php due to improper input sanitization. Attackers can b...

Mar 28, 2025
CVE-2025-30367
9.8

A SQL injection vulnerability in WeGIA web management software allows attackers to manipulate database queries through the nextPage parameter. This en...

Mar 27, 2025
CVE-2025-30364
9.8

A SQL injection vulnerability in WeGIA versions before 3.2.8 allows attackers to execute arbitrary SQL commands through the id_funcionario parameter i...

Mar 27, 2025
CVE-2025-25686
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through SEMCMS_Fuction.php in SEMCMS versions up to 5.0. Attackers can potential...

Mar 27, 2025
CVE-2024-42533
9.8

This SQL injection vulnerability in Convivance StandVoice's authentication module allows remote attackers to execute arbitrary SQL commands via the GE...

Mar 25, 2025
CVE-2025-1446
9.8

The Pods WordPress plugin before version 3.2.8.2 contains a SQL injection vulnerability due to insufficient input sanitization. This allows authentica...

Mar 23, 2025
CVE-2025-29980
9.8

A critical SQL injection vulnerability in eTRAKiT.net release 3.2.1.77 allows remote unauthenticated attackers to execute arbitrary SQL commands as th...

Mar 20, 2025
CVE-2024-12909
9.8

This SQL injection vulnerability in the FinanceChatLlamaPack allows attackers to execute arbitrary SQL queries through the database_agent's run_sql_qu...

Mar 20, 2025
CVE-2024-11958
9.8

A critical SQL injection vulnerability in the duckdb_retriever component of run-llama/llama_index allows attackers to execute arbitrary SQL commands. ...

Mar 20, 2025
CVE-2024-12016
9.8

This SQL injection vulnerability in CM Informatics CM News allows attackers to execute arbitrary SQL commands through unvalidated user input. All user...

Mar 20, 2025
CVE-2025-21619
9.8

This SQL injection vulnerability in GLPI allows administrator users to execute arbitrary SQL commands through rules configuration forms. Attackers wit...

Mar 18, 2025
CVE-2024-8997
9.8

This SQL injection vulnerability in Vestel EVC04 Configuration Interface allows attackers to execute arbitrary SQL commands through the web interface....

Mar 18, 2025
CVE-2025-25914
9.8

A SQL injection vulnerability in Online Exam Mastering System v1.0 allows remote attackers to execute arbitrary SQL commands via the fid parameter. Th...

Mar 17, 2025
CVE-2025-26163
9.8

CVE-2025-26163 is a critical SQL injection vulnerability in CM Soluces Informatica Ltda Auto Atendimento software versions 1.x.x. Attackers can exploi...

Mar 14, 2025
CVE-2025-25763
9.8

CVE-2025-25763 is a SQL injection vulnerability in crmeb CRMEB-KY software that allows attackers to execute arbitrary SQL commands through the getRead...

Mar 6, 2025
CVE-2024-12144
9.8

This SQL injection vulnerability in Finder Fire Safety Finder ERP/CRM (Old System) allows attackers to execute arbitrary SQL commands through the appl...

Mar 6, 2025
CVE-2024-12097
9.8

This SQL injection vulnerability in Boceksoft Informatics E-Travel allows attackers to execute arbitrary SQL commands on the database. It affects all ...

Mar 5, 2025
CVE-2025-27659
9.8

This SQL injection vulnerability in Vasion Print (formerly PrinterLogic) allows attackers to execute arbitrary SQL commands on the database. It affect...

Mar 5, 2025
CVE-2025-27640
9.8

This SQL injection vulnerability in Vasion Print (formerly PrinterLogic) allows attackers to execute arbitrary SQL commands on the database. It affect...

Mar 5, 2025
CVE-2025-26136
9.8

A SQL injection vulnerability in mysiteforme allows attackers to execute arbitrary SQL commands on the database. This affects all mysiteforme installa...

Mar 4, 2025
CVE-2024-50706
9.8

This is an unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ that allows remote attackers to execute arbitrary SQL quer...

Mar 4, 2025
CVE-2025-1871
9.8

A SQL injection vulnerability in 101news version 1.0 allows attackers to execute arbitrary SQL commands through the 'category' and 'subcategory' param...

Mar 3, 2025
CVE-2025-1873
9.8

A critical SQL injection vulnerability exists in 101news CMS version 1.0 through the 'pagetitle' and 'pagedescription' parameters in admin/contactus.p...

Mar 3, 2025
CVE-2025-1875
9.8

CVE-2025-1875 is a critical SQL injection vulnerability in 101news version 1.0 that allows attackers to execute arbitrary SQL commands through the 'se...

Mar 3, 2025
CVE-2025-1869
9.8

A SQL injection vulnerability in 101news version 1.0 allows attackers to execute arbitrary SQL commands through the username parameter in admin/check_...

Mar 3, 2025
CVE-2024-55160
9.8

GFast versions 2 through 3.2 contain a SQL injection vulnerability in the OrderBy parameter at the /system/operLog/list endpoint. This allows attacker...

Feb 27, 2025
CVE-2025-1751
9.8

A SQL injection vulnerability in Ciges 2.15.5 allows attackers to manipulate database operations through the $idServicio parameter in the /modules/aja...

Feb 27, 2025
CVE-2025-25516
9.8

Seacms versions up to 13.3 contain a SQL injection vulnerability in admin_paylog.php that allows attackers to execute arbitrary SQL commands. This aff...

Feb 25, 2025
CVE-2025-25519
9.8

SeaCMS versions up to 13.3 contain a SQL injection vulnerability in the admin_zyk.php file that allows attackers to execute arbitrary SQL commands. Th...

Feb 25, 2025
CVE-2025-25521
9.8

Seacms versions up to 13.3 contain a SQL injection vulnerability in admin_type_news.php that allows attackers to execute arbitrary SQL commands. This ...

Feb 25, 2025
CVE-2025-27135
9.8

CVE-2025-27135 is a critical SQL injection vulnerability in RAGFlow's ExeSQL component that allows attackers to execute arbitrary SQL commands on the ...

Feb 25, 2025
CVE-2025-22974
9.8

This SQL injection vulnerability in SeaCMS allows remote attackers to execute arbitrary SQL commands through the DoTranExecSql parameter in phome.php....

Feb 24, 2025
CVE-2024-53544
9.8

This SQL injection vulnerability in NovaCHRON Smart Time Plus allows attackers to execute arbitrary SQL commands through the getCookieNames method. Or...

Feb 24, 2025
CVE-2025-25513
9.8

Seacms versions up to 13.3 contain a SQL injection vulnerability in admin_members.php that allows attackers to execute arbitrary SQL commands. This af...

Feb 24, 2025

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,468 CVEs classified as CWE-89, with 1,913 rated critical and 1,904 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free