CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,482
Total CVEs
1,924
Critical
1,907
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
241
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 126
2 Oretnom23 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,482)

CVE-2025-27096
9.8

A SQL injection vulnerability in WeGIA's personalizacao_upload.php endpoint allows authenticated attackers to execute arbitrary SQL queries. This can ...

Feb 20, 2025
CVE-2025-26617
9.8

A SQL injection vulnerability in WeGIA's historico_paciente.php endpoint allows attackers to execute arbitrary SQL queries. This could lead to unautho...

Feb 18, 2025
CVE-2025-26610
9.8

A SQL injection vulnerability in WeGIA's restaurar_produto_desocultar.php endpoint allows authenticated attackers to execute arbitrary SQL queries. Th...

Feb 18, 2025
CVE-2025-26612
9.8

CVE-2025-26612 is a critical SQL injection vulnerability in WeGIA's adicionar_almoxarife.php endpoint that allows attackers to execute arbitrary SQL q...

Feb 18, 2025
CVE-2025-26606
9.8

A SQL injection vulnerability in WeGIA's informacao_adicional.php endpoint allows attackers to execute arbitrary SQL queries. This could lead to unaut...

Feb 18, 2025
CVE-2025-26608
9.8

A SQL injection vulnerability in WeGIA's dependente_docdependente.php endpoint allows attackers to execute arbitrary SQL queries. This could lead to u...

Feb 18, 2025
CVE-2025-1023
9.8

A critical SQL injection vulnerability in ChurchCRM versions 5.13.0 and earlier allows attackers to execute arbitrary database queries through the Edi...

Feb 18, 2025
CVE-2025-25388
9.8

A SQL injection vulnerability in PHPGurukul Land Record System v1.0 allows remote attackers to execute arbitrary SQL commands via the editid parameter...

Feb 13, 2025
CVE-2025-25349
9.8

CVE-2025-25349 is a critical SQL injection vulnerability in PHPGurukul Daily Expense Tracker System v1.1 that allows attackers to execute arbitrary SQ...

Feb 12, 2025
CVE-2025-22992
9.8

A critical SQL injection vulnerability in Emoncms allows attackers to execute arbitrary SQL commands through the /feed/insert.json endpoint. This affe...

Feb 6, 2025
CVE-2024-57430
9.8

An SQL injection vulnerability in PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries through the column parameter i...

Feb 6, 2025
CVE-2020-36084
9.8

This SQL injection vulnerability in Responsive E-Learning System 1.0 allows remote attackers to execute arbitrary SQL commands through the 'id' parame...

Feb 5, 2025
CVE-2025-24957
9.8

This SQL injection vulnerability in WeGIA's get_detalhes_socio.php endpoint allows authenticated attackers to execute arbitrary SQL queries. Attackers...

Feb 3, 2025
CVE-2025-24905
9.8

CVE-2025-24905 is a critical SQL injection vulnerability in WeGIA's get_codigobarras_cobranca.php endpoint that allows authenticated attackers to exec...

Feb 3, 2025
CVE-2024-57098
9.8

Moss v0.1.3 contains an SQL injection vulnerability in the order parameter that allows attackers to execute arbitrary SQL commands. This affects all s...

Feb 3, 2025
CVE-2025-22957
9.8

An unauthenticated SQL injection vulnerability in ZZCMS front-end allows attackers to execute arbitrary SQL commands against the database. This affect...

Jan 31, 2025
CVE-2025-0929
9.8

SQL injection vulnerability in TeamCal Neo version 3.8.2 allows attackers to execute arbitrary SQL commands via the 'abs' parameter. This could lead t...

Jan 31, 2025
CVE-2024-57328
9.8

This SQL injection vulnerability in Online Food Ordering System v1.0 allows attackers to bypass authentication by injecting malicious SQL queries thro...

Jan 23, 2025
CVE-2023-37777
9.8

A critical SQL injection vulnerability in Synnefo Internet Management Software (IMS) allows attackers to execute arbitrary SQL commands via a specific...

Jan 22, 2025
CVE-2023-27112
9.8

This SQL injection vulnerability in pearProjectApi allows attackers to execute arbitrary SQL commands through the projectCode parameter. Any system ru...

Jan 21, 2025
CVE-2025-23218
9.8

CVE-2025-23218 is a critical SQL injection vulnerability in WeGIA's adicionar_especie.php endpoint that allows attackers to execute arbitrary SQL comm...

Jan 20, 2025
CVE-2025-23220
9.8

CVE-2025-23220 is a critical SQL injection vulnerability in WeGIA's adicionar_raca.php endpoint that allows attackers to execute arbitrary SQL command...

Jan 20, 2025
CVE-2025-0585
9.8

CVE-2025-0585 is a critical SQL injection vulnerability in a+HRD software from aEnrich Technology that allows unauthenticated remote attackers to exec...

Jan 20, 2025
CVE-2024-57035
9.8

CVE-2024-57035 is a critical SQL injection vulnerability in WeGIA v3.2.0 that allows attackers to execute arbitrary SQL commands via the nextPage para...

Jan 17, 2025
CVE-2024-57034
9.8

CVE-2024-57034 is a critical SQL injection vulnerability in WeGIA versions before 3.2.0 that allows attackers to execute arbitrary SQL commands throug...

Jan 17, 2025
CVE-2024-57031
9.8

WeGIA versions below 3.2.0 contain a SQL injection vulnerability in the /funcionario/remuneracao.php endpoint via the id_funcionario parameter. This a...

Jan 17, 2025
CVE-2024-57768
9.8

This SQL injection vulnerability in JFinalOA allows attackers to execute arbitrary SQL commands through the validRoleKey parameter. It affects all sys...

Jan 16, 2025
CVE-2025-0455
9.8

CVE-2025-0455 is a critical SQL injection vulnerability in NetVision Information's airPASS product that allows unauthenticated remote attackers to exe...

Jan 16, 2025
CVE-2024-8855
9.8

This SQL injection vulnerability in the WordPress Auction Plugin allows authenticated users with editor privileges or higher to execute arbitrary SQL ...

Jan 7, 2025
CVE-2024-56801
9.8

This CVE describes a blind SQL injection vulnerability in the Tasklists plugin for GLPI. Attackers can exploit this to execute arbitrary SQL commands ...

Dec 30, 2024
CVE-2024-47926
9.8

CVE-2024-47926 is a critical SQL injection vulnerability in Tecnick TCExam that allows attackers to execute arbitrary SQL commands. This affects all T...

Dec 30, 2024
CVE-2024-50716
9.8

A critical SQL injection vulnerability in Smart Agent v1.1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in the /...

Dec 27, 2024
CVE-2024-50713
9.8

SmartAgent v1.1.0 contains a SQL injection vulnerability in the /tests/interface.php endpoint via the id parameter. This allows attackers to execute a...

Dec 27, 2024
CVE-2024-55509
9.8

This SQL injection vulnerability in CodeAstro Complaint Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the id pa...

Dec 20, 2024
CVE-2024-12727
9.8

This critical vulnerability allows unauthenticated attackers to execute SQL injection attacks against Sophos Firewall's email protection feature. Succ...

Dec 19, 2024
CVE-2024-8972
9.8

This SQL injection vulnerability in Mobil365 Informatics Saha365 App allows attackers to execute arbitrary SQL commands by injecting malicious input. ...

Dec 17, 2024
CVE-2024-52057
9.8

This SQL injection vulnerability in RTI Connext Professional's Queuing Service allows attackers to execute arbitrary SQL commands by injecting malicio...

Dec 13, 2024
CVE-2024-11837
9.8

This CVE describes an N1QL injection vulnerability in PlexTrac that allows attackers to execute arbitrary N1QL commands against the underlying databas...

Dec 13, 2024
CVE-2024-54810
9.8

A SQL injection vulnerability in the PHPGurukul Pre-School Enrollment System allows remote attackers to execute arbitrary SQL commands via the mobilen...

Dec 12, 2024
CVE-2024-55099
9.8

A SQL injection vulnerability in the phpgurukul Online Nurse Hiring System v1.0 allows remote attackers to execute arbitrary SQL commands via the user...

Dec 12, 2024
CVE-2024-54842
9.8

This SQL injection vulnerability in phpgurukul Online Nurse Hiring System v1.0 allows attackers to execute arbitrary SQL commands through the mobileno...

Dec 12, 2024
CVE-2024-53480
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the emailcont parameter in login.php. It affects all users of Phpgurukul...

Dec 10, 2024
CVE-2024-55586
9.8

CVE-2024-55586 is an SQL injection vulnerability in Nette Database that occurs when untrusted filter data is passed directly to the where() method. Th...

Dec 10, 2024
CVE-2024-54923
9.8

A SQL injection vulnerability in kashipara E-learning Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the departm...

Dec 9, 2024
CVE-2024-54925
9.8

A SQL injection vulnerability in kashipara E-learning Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the id para...

Dec 9, 2024
CVE-2024-54931
9.8

A SQL injection vulnerability in kashipara E-learning Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the id para...

Dec 9, 2024
CVE-2024-54934
9.8

Kashipara E-learning Management System v1.0 contains a SQL injection vulnerability in the delete_class.php admin endpoint. This allows attackers to ex...

Dec 9, 2024
CVE-2024-54920
9.8

A SQL injection vulnerability in kashipara E-learning Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the teacher...

Dec 9, 2024
CVE-2024-8259
9.8

This SQL injection vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows attackers to execute arbitrary SQL co...

Dec 9, 2024
CVE-2024-53947
9.8

This SQL injection vulnerability in Apache Superset allows attackers to bypass SQL authorization by exploiting unvalidated PostgreSQL functions. Attac...

Dec 9, 2024

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,482 CVEs classified as CWE-89, with 1,924 rated critical and 1,907 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free