CWE-89: SQL Injection

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

4,487
Total CVEs
1,926
Critical
1,910
High
8.4
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
241
2025
1,195
2024
1,299
2023
723
2022
527

Top Affected Vendors

1 Phpgurukul 126
2 Oretnom23 125
3 Projectworlds 51
4 Code Projects 50
5 Siemens 45
6 Wegia 42
7 Campcodes 41
8 Janobe 38
9 Mayurik 37
10 Openlinksw 35

All SQL Injection CVEs (4,487)

CVE-2024-45249
9.8

This SQL injection vulnerability in Cavok software allows attackers to execute arbitrary SQL commands by injecting malicious input. It affects systems...

Oct 6, 2024
CVE-2024-47849
9.8

This SQL injection vulnerability in MediaWiki's Cargo extension allows attackers to execute arbitrary SQL commands on the database. It affects MediaWi...

Oct 5, 2024
CVE-2024-43699
9.8

Delta Electronics DIAEnergie has an SQL injection vulnerability in the AM_RegReport.aspx script that allows unauthenticated attackers to extract datab...

Oct 3, 2024
CVE-2024-45999
9.8

A SQL injection vulnerability in Cloudlog 2.6.15 allows attackers to execute arbitrary SQL commands via the station_id parameter in the get_station_in...

Oct 1, 2024
CVE-2024-8607
9.8

This SQL injection vulnerability in Oceanic Software ValeApp allows attackers to execute arbitrary SQL commands through the application. It affects al...

Sep 27, 2024
CVE-2024-8275
9.8

This SQL injection vulnerability in The Events Calendar WordPress plugin allows unauthenticated attackers to execute arbitrary SQL queries through the...

Sep 25, 2024
CVE-2024-8877
9.8

This SQL injection vulnerability in Riello Netman 204 allows attackers to execute arbitrary SQL commands on the SQLite measurement database. It affect...

Sep 25, 2024
CVE-2024-46374
9.8

Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function that allows attackers to execute arbi...

Sep 18, 2024
CVE-2024-44542
9.8

A SQL injection vulnerability in ToDesk v1.1 allows remote attackers to execute arbitrary SQL commands via the /todesk.com/news.html parameter. This c...

Sep 18, 2024
CVE-2024-6401
9.8

This SQL injection vulnerability in SFS Consulting InsureE GL allows attackers to execute arbitrary SQL commands through the application. All organiza...

Sep 16, 2024
CVE-2024-44430
9.8

This SQL injection vulnerability in Best Free Law Office Management Software v1.0 allows attackers to execute arbitrary SQL commands through the regis...

Sep 13, 2024
CVE-2024-44541
9.8

This SQL injection vulnerability in evilnapsis Inventio Lite allows attackers to execute arbitrary SQL commands through the username parameter during ...

Sep 11, 2024
CVE-2024-27112
9.8

An unauthenticated SQL injection vulnerability exists in SO Planning tool when public view is enabled, allowing attackers to execute arbitrary SQL com...

Sep 11, 2024
CVE-2024-8503
9.8

An unauthenticated attacker can exploit a time-based SQL injection vulnerability in VICIdial to enumerate database records, including plaintext creden...

Sep 10, 2024
CVE-2024-6924
9.8

This SQL injection vulnerability in the TrueBooker WordPress plugin allows unauthenticated attackers to execute arbitrary SQL commands via AJAX reques...

Sep 8, 2024
CVE-2024-6928
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Opti Marketing plugin. Attackers ca...

Sep 8, 2024
CVE-2024-8395
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on FlyCASS CASS and KCM systems. Attackers can potentially read,...

Sep 5, 2024
CVE-2024-8469
9.8

This is a critical SQL injection vulnerability in a job portal application's admin interface. Attackers can exploit it by sending malicious SQL querie...

Sep 5, 2024
CVE-2024-8465
9.8

This SQL injection vulnerability in a job portal's admin interface allows attackers to execute arbitrary SQL queries through the user_id parameter. At...

Sep 5, 2024
CVE-2024-8467
9.8

This SQL injection vulnerability in Job Portal software allows attackers to execute arbitrary SQL queries through the id parameter in the admin catego...

Sep 5, 2024
CVE-2024-7076
9.8

This SQL injection vulnerability in Semtek Sempos allows attackers to execute arbitrary SQL commands through blind injection techniques. It affects al...

Sep 4, 2024
CVE-2024-7078
9.8

This SQL injection vulnerability in Semtek Sempos software allows attackers to execute arbitrary SQL commands on the database. All users running Semte...

Sep 4, 2024
CVE-2024-6926
9.8

The Viral Signup WordPress plugin through version 2.1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrar...

Sep 4, 2024
CVE-2024-44921
9.8

SeaCMS v12.9 contains a SQL injection vulnerability in the id parameter at /dmplayer/dmku/index.php?ac=del. This allows attackers to execute arbitrary...

Sep 3, 2024
CVE-2024-45622
9.8

This vulnerability allows attackers to bypass authentication in ASIS (Aplikasi Sistem Sekolah) by exploiting SQL injection in the username parameter o...

Sep 2, 2024
CVE-2024-6919
9.8

This SQL injection vulnerability in NAC Telecommunication Systems' NACPremium software allows attackers to execute arbitrary SQL commands without auth...

Sep 2, 2024
CVE-2024-43772
9.8

This SQL injection vulnerability in Easytest Online Test Platform allows remote attackers to execute arbitrary SQL commands via the uid parameter in t...

Sep 2, 2024
CVE-2024-6670
9.8

An unauthenticated SQL injection vulnerability in WhatsUp Gold allows attackers to retrieve encrypted user passwords. This affects all WhatsUp Gold ve...

Aug 29, 2024
CVE-2024-41370
9.8

Organizr v1.90 contains a SQL injection vulnerability in the chat/setlike.php endpoint that allows attackers to execute arbitrary SQL commands. This a...

Aug 29, 2024
CVE-2024-41372
9.8

Organizr v1.90 contains a SQL injection vulnerability in chat/settyping.php that allows attackers to execute arbitrary SQL commands. This affects all ...

Aug 29, 2024
CVE-2024-29729
9.8

This SQL injection vulnerability in SportsNET version 4.0.1 allows attackers to execute arbitrary SQL queries through the 'url' parameter in the gener...

Aug 29, 2024
CVE-2024-29731
9.8

SQL injection vulnerabilities in SportsNET version 4.0.1 allow attackers to execute arbitrary SQL queries through the checkBlindFields endpoint. This ...

Aug 29, 2024
CVE-2024-29723
9.8

SQL injection vulnerability in SportsNET version 4.0.1 allows attackers to execute arbitrary SQL queries through the 'categoria' parameter. This could...

Aug 29, 2024
CVE-2024-29725
9.8

SQL injection vulnerabilities in SportsNET version 4.0.1 allow attackers to execute arbitrary SQL queries through the sort_bloques parameter. This cou...

Aug 29, 2024
CVE-2024-29727
9.8

This SQL injection vulnerability in SportsNET version 4.0.1 allows attackers to execute arbitrary SQL queries through the sendParticipationRemember en...

Aug 29, 2024
CVE-2024-7857
9.8

The Media Library Folders WordPress plugin has a second-order SQL injection vulnerability that allows authenticated attackers with subscriber-level ac...

Aug 29, 2024
CVE-2024-7071
9.8

This SQL injection vulnerability in Brain Low-Code allows attackers to execute arbitrary SQL commands through the Hibernate framework. It affects all ...

Aug 27, 2024
CVE-2024-8161
9.8

A critical SQL injection vulnerability in ATISolutions CIGES allows remote attackers to execute arbitrary SQL queries through the idCentro parameter i...

Aug 26, 2024
CVE-2024-32501
9.8

A SQL injection vulnerability in Centreon Web's updateServiceHost function allows attackers to execute arbitrary SQL commands. This affects all Centre...

Aug 23, 2024
CVE-2024-42781
9.8

A SQL injection vulnerability in Kashipara Music Management System v1.0 allows remote attackers to bypass authentication and execute arbitrary SQL com...

Aug 21, 2024
CVE-2024-42783
9.8

Kashipara Music Management System v1.0 contains a SQL injection vulnerability in the manage_playlist_items.php endpoint via the 'pid' parameter. Attac...

Aug 21, 2024
CVE-2024-33872
9.8

This SQL injection vulnerability in Keyfactor Command allows attackers to execute arbitrary SQL commands on the database. Successful exploitation coul...

Aug 20, 2024
CVE-2024-42573
9.8

This CVE describes a SQL injection vulnerability in the School Management System via the 'medium' parameter in dtmarks.php. Attackers can execute arbi...

Aug 20, 2024
CVE-2024-42575
9.8

This SQL injection vulnerability in the School Management System allows attackers to execute arbitrary SQL commands through the 'medium' parameter in ...

Aug 20, 2024
CVE-2024-42562
9.8

This SQL injection vulnerability in Pharmacy Management System allows attackers to execute arbitrary SQL commands through the invoice_number parameter...

Aug 20, 2024
CVE-2024-42565
9.8

This CVE describes a critical SQL injection vulnerability in an ERP system's contact deletion function. Attackers can execute arbitrary SQL commands b...

Aug 20, 2024
CVE-2024-42567
9.8

This SQL injection vulnerability in the School Management System allows attackers to execute arbitrary SQL commands through the 'sid' parameter in sea...

Aug 20, 2024
CVE-2024-42569
9.8

This SQL injection vulnerability in the School Management System allows attackers to execute arbitrary SQL commands via the 'medium' parameter in paid...

Aug 20, 2024
CVE-2024-42571
9.8

This SQL injection vulnerability in School Management System allows attackers to execute arbitrary SQL commands via the 'medium' parameter in insertat...

Aug 20, 2024
CVE-2024-42556
9.8

This SQL injection vulnerability in Hotel Management System allows attackers to execute arbitrary SQL commands through the room_type parameter. It aff...

Aug 20, 2024

About SQL Injection (CWE-89)

The product constructs all or part of an SQL command using externally-influenced input, but does not neutralize special elements that could modify the intended SQL command.

Our database tracks 4,487 CVEs classified as CWE-89, with 1,926 rated critical and 1,910 rated high severity. The average CVSS score for SQL Injection vulnerabilities is 8.4.

External reference: View CWE-89 on MITRE CWE →

Monitor SQL Injection Vulnerabilities

Get alerted when new SQL Injection CVEs affect your infrastructure.

Start Monitoring Free