CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,487
Total CVEs
1,926
Critical
1,910
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
241
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 126
2 Oretnom23 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,487)

CVE-2024-50387
9.8

A critical SQL injection vulnerability in QNAP SMB Service allows remote attackers to execute arbitrary SQL commands. This affects QNAP NAS devices ru...

Dec 6, 2024
CVE-2024-50389
9.8

A SQL injection vulnerability in QuRouter allows remote attackers to execute arbitrary SQL commands. This affects all QuRouter systems running vulnera...

Dec 6, 2024
CVE-2024-52335
9.8

This is a critical SQL injection vulnerability in Siemens Healthineers syngo.plaza VB30E medical imaging software. Attackers with application access c...

Dec 6, 2024
CVE-2024-53908
9.8

This vulnerability allows SQL injection attacks in Django applications when using the django.db.models.fields.json.HasKey lookup directly with untrust...

Dec 6, 2024
CVE-2024-41579
9.8

CVE-2024-41579 is a critical SQL injection vulnerability in DTStack Taier 1.4.0 that allows remote attackers to execute arbitrary SQL commands via the...

Dec 5, 2024
CVE-2024-52724
9.8

ZZCMS 2023 contains a SQL injection vulnerability in the /q/show.php endpoint that allows attackers to execute arbitrary SQL commands. This affects al...

Dec 2, 2024
CVE-2024-53504
9.8

A SQL injection vulnerability in Siyuan 3.1.11 allows attackers to execute arbitrary SQL commands via the notebook parameter in the /searchHistory end...

Nov 29, 2024
CVE-2024-53506
9.8

A SQL injection vulnerability in Siyuan 3.1.11 allows attackers to execute arbitrary SQL commands via the ids array parameter in the /batchGetBlockAtt...

Nov 29, 2024
CVE-2024-50942
9.8

This SQL injection vulnerability in qiwen-file v1.4.0 allows attackers to execute arbitrary SQL commands through the NoticeMapper.xml component. This ...

Nov 26, 2024
CVE-2024-50672
9.8

This NoSQL injection vulnerability in Adapt Learning Authoring Tool allows unauthenticated attackers to reset any user's password, including administr...

Nov 25, 2024
CVE-2024-53438
9.8

CVE-2024-53438 is a critical SQL injection vulnerability in ChurchCRM 5.7.0 that allows attackers to execute arbitrary SQL commands by manipulating th...

Nov 22, 2024
CVE-2024-52675
9.8

CVE-2024-52675 is a critical SQL injection vulnerability in SourceCodester Sentiment Based Movie Rating System 1.0 that allows attackers to execute ar...

Nov 19, 2024
CVE-2024-44756
9.8

NUS-M9 ERP Management Software v3.0.0 contains a SQL injection vulnerability in the login endpoint that allows attackers to execute arbitrary SQL comm...

Nov 18, 2024
CVE-2024-50724
9.8

KASO v9.0 contains a SQL injection vulnerability in the person_id parameter at /cardcase/editcard.jsp that allows attackers to execute arbitrary SQL c...

Nov 15, 2024
CVE-2024-50833
9.8

This SQL injection vulnerability in the KASHIPARA E-learning Management System login page allows attackers to execute arbitrary SQL commands through u...

Nov 14, 2024
CVE-2024-50330
9.8

This critical SQL injection vulnerability in Ivanti Endpoint Manager allows remote unauthenticated attackers to execute arbitrary SQL commands, potent...

Nov 12, 2024
CVE-2024-44546
9.8

PowerJob versions 3.20 and above contain a SQL injection vulnerability in the version parameter that allows attackers to execute arbitrary SQL command...

Nov 11, 2024
CVE-2024-50989
9.8

This SQL injection vulnerability in PHPGurukul Online Marriage Registration System v1.0 allows unauthenticated attackers to execute arbitrary SQL comm...

Nov 11, 2024
CVE-2024-11020
9.8

CVE-2024-11020 is a critical SQL injection vulnerability in Webopac software from Grand Vice info that allows unauthenticated attackers to execute arb...

Nov 11, 2024
CVE-2024-11016
9.8

CVE-2024-11016 is a critical SQL injection vulnerability in Webopac from Grand Vice info that allows unauthenticated attackers to execute arbitrary SQ...

Nov 11, 2024
CVE-2024-51211
9.8

This SQL injection vulnerability in OS4ED openSIS-Classic allows attackers to execute arbitrary SQL commands by manipulating the $username_stn_id para...

Nov 8, 2024
CVE-2024-50766
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the id parameter in takeSurvey.php. It affects all deployments of Source...

Nov 7, 2024
CVE-2024-51327
9.8

This SQL injection vulnerability in ProjectWorld's Travel Management System v1.0 allows attackers to bypass authentication by injecting malicious SQL ...

Nov 4, 2024
CVE-2024-7456
9.8

This SQL injection vulnerability in lunary-ai/lunary v1.4.2 allows attackers to execute arbitrary SQL commands through the `/api/v1/external-users` en...

Nov 1, 2024
CVE-2024-51064
9.8

This SQL injection vulnerability in Phpgurukul Teachers Record Management System v2.1 allows attackers to execute arbitrary SQL commands via the tid p...

Oct 31, 2024
CVE-2024-48573
9.8

A NoSQL injection vulnerability in AquilaCMS allows unauthenticated attackers to reset any user or administrator account passwords via the password re...

Oct 29, 2024
CVE-2024-8309
9.8

This vulnerability allows SQL injection through prompt injection in langchain-ai/langchain's GraphCypherQAChain class. Attackers can manipulate databa...

Oct 29, 2024
CVE-2024-7042
9.8

A prompt injection vulnerability in langchain-ai/langchainjs GraphCypherQAChain class allows attackers to inject SQL commands through manipulated prom...

Oct 29, 2024
CVE-2024-48356
9.8

LyLme Spage versions up to 1.6.0 contain a SQL injection vulnerability in the /admin/group.php endpoint. This allows attackers to execute arbitrary SQ...

Oct 28, 2024
CVE-2024-48357
9.8

LyLme Spage versions 1.2.0 through 1.6.0 contain a SQL injection vulnerability in the /admin/apply.php endpoint. This allows attackers to execute arbi...

Oct 28, 2024
CVE-2024-10440
9.8

The eHDR CTMS from Sunnet contains a SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL commands. This ...

Oct 28, 2024
CVE-2024-48580
9.8

This SQL injection vulnerability in the Best Courier Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the email pa...

Oct 25, 2024
CVE-2024-44812
9.8

This SQL injection vulnerability in Online Complaint Site v1.0 allows remote attackers to execute arbitrary SQL commands via the username and password...

Oct 22, 2024
CVE-2024-48509
9.8

Learning with Texts (LWT) 2.0.3 contains a SQL injection vulnerability that allows attackers to manipulate database queries through URL parameters. Th...

Oct 21, 2024
CVE-2016-15040
9.8

This SQL injection vulnerability in the Kento Post View Counter WordPress plugin allows unauthenticated attackers to execute arbitrary SQL queries thr...

Oct 16, 2024
CVE-2024-48411
9.8

CVE-2024-48411 is a critical SQL injection vulnerability in itsourcecode Online Tours and Travels Management System v1.0 that allows attackers to exec...

Oct 15, 2024
CVE-2024-48283
9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the searchkey parameter in the admin search functionality of Phpgurukul ...

Oct 15, 2024
CVE-2024-9925
9.8

A critical SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0 allows remote attackers to execute arbitrary SQL commands via the ...

Oct 15, 2024
CVE-2024-9982
9.8

CVE-2024-9982 is a critical SQL injection vulnerability in the AIM LINE Marketing Platform from Esi Technology. Unauthenticated attackers can execute ...

Oct 15, 2024
CVE-2024-9972
9.8

ChanGate Property Management System contains an unauthenticated SQL injection vulnerability (CWE-89) that allows remote attackers to execute arbitrary...

Oct 15, 2024
CVE-2024-46535
9.8

Jepaas v7.2.8 contains a SQL injection vulnerability in the orderSQL parameter at /homePortal/loadUserMsg endpoint. This allows attackers to execute a...

Oct 14, 2024
CVE-2024-48251
9.8

CVE-2024-48251 is an unauthenticated SQL injection vulnerability in Wavelog 1.8.5 that allows attackers to execute arbitrary SQL commands through the ...

Oct 14, 2024
CVE-2024-48253
9.8

Cloudlog 2.6.15 contains an unauthenticated SQL injection vulnerability in the Oqrs.php delete_oqrs_line function. This allows attackers to execute ar...

Oct 14, 2024
CVE-2024-7099
9.8

CVE-2024-7099 is a critical SQL injection vulnerability in netease-youdao/qanything version 1.4.1 that allows attackers to execute arbitrary SQL queri...

Oct 13, 2024
CVE-2024-46532
9.8

CVE-2024-46532 is a critical SQL injection vulnerability in OpenHIS v1.0 that allows attackers to execute arbitrary SQL commands through the refund fu...

Oct 11, 2024
CVE-2024-9796
9.8

The WP-Advanced-Search WordPress plugin before version 3.3.9.2 contains an SQL injection vulnerability in the 't' parameter that is not properly sanit...

Oct 10, 2024
CVE-2024-43468
KEV EPSS 87.5% 9.8

CVE-2024-43468 is a critical SQL injection vulnerability in Microsoft Configuration Manager that allows remote attackers to execute arbitrary code on ...

Oct 8, 2024
CVE-2024-45918
9.8

This SQL injection vulnerability in Fujian Kelixin Communication Command and Dispatch Platform allows attackers to execute arbitrary SQL commands via ...

Oct 8, 2024
CVE-2024-8911
9.8

This SQL injection vulnerability in the LatePoint WordPress plugin allows unauthenticated attackers to change user passwords. It affects versions up t...

Oct 8, 2024
CVE-2024-9574
9.8

This SQL injection vulnerability in SOPlanning versions before 1.45 allows remote attackers to execute arbitrary SQL queries through the 'by' paramete...

Oct 7, 2024

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,487 CVEs classified as CWE-89, with 1,926 rated critical and 1,910 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free