CWE-89— SQL Injection
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.— MITRE CWE catalog
21,098 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-89page 1 of 422
- CVE-2026-72898CRITICALCVSS 10.0EG 10.0⚠ KEV2026-08-10
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
- CVE-2026-76461CRITICALCVSS 9.8EG 9.8⚠ KEV2026-09-14
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vu…
- CVE-2026-9586CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-17
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into…
- CVE-2026-9082CRITICALCVSS 9.8EG 9.8⚠ KEV2026-05-20
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.…
- CVE-2026-42208CRITICALCVSS 9.8EG 9.8⚠ KEV2026-05-08
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text …
- CVE-2026-21643CRITICALCVSS 9.8EG 9.8⚠ KEV2026-02-06
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted …
- CVE-2025-57819CRITICALCVSS 9.8EG 9.8⚠ KEV2025-08-28
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary …
- CVE-2025-25257CRITICALCVSS 9.8EG 9.8⚠ KEV2025-07-17
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.…
- CVE-2024-43468CRITICALCVSS 9.8EG 9.8⚠ KEV2024-10-08
Microsoft Configuration Manager Remote Code Execution Vulnerability
- CVE-2024-6670CRITICALCVSS 9.8EG 9.8⚠ KEV2024-08-29
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
- CVE-2023-48788CRITICALCVSS 9.8EG 9.8⚠ KEV2024-03-12
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via…
- CVE-2023-34362CRITICALCVSS 9.8EG 9.8⚠ KEV2023-06-02
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an u…
- CVE-2021-44026CRITICALCVSS 9.8EG 9.8⚠ KEV2021-11-19
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
- CVE-2021-42258CRITICALCVSS 9.8EG 9.8⚠ KEV2021-10-22
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (…
- CVE-2021-20028CRITICALCVSS 9.8EG 9.8⚠ KEV2021-08-04
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier
- CVE-2021-27101CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-16
Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
- CVE-2021-20016CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-04
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build v…
- CVE-2020-29574CRITICALCVSS 9.8EG 9.8⚠ KEV2020-12-11
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
- CVE-2020-17463CRITICALCVSS 9.8EG 9.8⚠ KEV2020-08-13
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
- CVE-2020-12271CRITICALCVSS 9.8EG 9.8⚠ KEV2020-04-27
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or …
- CVE-2020-5722CRITICALCVSS 9.8EG 9.8⚠ KEV2020-03-23
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 o…
- CVE-2019-12989CRITICALCVSS 9.8EG 9.8⚠ KEV2019-07-16
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
- CVE-2018-7841CRITICALCVSS 9.8EG 9.8⚠ KEV2019-05-22
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
- CVE-2017-18362CRITICALCVSS 9.8EG 9.8⚠ KEV2019-02-05
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wi…
- CVE-2016-2386CRITICALCVSS 9.8EG 9.8⚠ KEV2016-02-16
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
- CVE-2024-29824CRITICALCVSS 8.8EG 9.6⚠ KEV2024-05-31
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
- CVE-2024-9465CRITICALCVSS 9.1EG 9.1⚠ KEV2024-10-09
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers…
- CVE-2023-46748CRITICALCVSS 8.8EG 9.0⚠ KEV2023-10-26
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresse…
- CVE-2019-7481CRITICALCVSS 7.5EG 9.0⚠ KEV2019-12-17
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.
- CVE-2024-9379CRITICALCVSS 7.2EG 9.0⚠ KEV2024-10-08
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
- CVE-2026-60137CRITICALCVSS 5.9EG 9.0⚠ KEV2026-07-17
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
- CVE-2025-25181CRITICALCVSS 5.8EG 9.0⚠ KEV2025-02-03
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.
- CVE-2026-12260CRITICALCVSS 10.0EG 10.02026-10-08
SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, e…
- CVE-2026-74820CRITICALCVSS 10.0EG 10.02026-08-27
ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against th…
- CVE-2026-20030CRITICALCVSS 10.0EG 10.02026-08-19
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address…
- CVE-2026-72811CRITICALCVSS 10.0EG 10.02026-08-14
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword int…
- CVE-2026-72851CRITICALCVSS 10.0EG 10.02026-08-13
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads th…
- CVE-2026-72899CRITICALCVSS 10.0EG 10.02026-08-10
Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.
- CVE-2026-48330CRITICALCVSS 10.0EG 10.02026-08-03
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker…
- CVE-2026-69085CRITICALCVSS 10.0EG 10.02026-08-03
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpo…
- CVE-2026-69084CRITICALCVSS 10.0EG 10.02026-08-03
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. The endpo…
- CVE-2026-69083CRITICALCVSS 10.0EG 10.02026-08-03
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-co…
- CVE-2026-52887CRITICALCVSS 10.0EG 10.02026-07-15
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter…
- CVE-2026-8054CRITICALCVSS 10.0EG 10.02026-05-27
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11.04-1 through 26.04.28-02 allows remote …
- CVE-2026-42287CRITICALCVSS 10.0EG 10.02026-05-08
Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially leading to complete database compromise…
- CVE-2026-3325CRITICALCVSS 10.0EG 10.02026-04-29
SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. The vulnerability arises from inadequate validation and sanitisation of user input. Spe…
- CVE-2025-10878CRITICALCVSS 10.0EG 10.02026-02-03
A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vulnerable to SQL injection, allowing unauthenticated attackers to bypass authent…
- CVE-2025-57792CRITICALCVSS 10.0EG 10.02026-01-28
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application endpoint. An attacker can supply crafted input that is executed as part of backend database…
- CVE-2025-65091CRITICALCVSS 10.0EG 10.02026-01-10
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing dat…
- CVE-2024-57521CRITICALCVSS 10.0EG 10.02025-12-23
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.
Map vulnerabilities like CWE-89 to your infrastructure
EchelonGraph correlates every CVE — across CWE-89 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →