CWE-89— SQL Injection
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.— MITRE CWE catalog
21,099 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-89page 2 of 422
- CVE-2025-63689CRITICALCVSS 10.0EG 10.02025-11-07
Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) allows a remote attacker to execute arbitrary code via the orderby parameter
- CVE-2025-57870CRITICALCVSS 10.0EG 10.02025-10-22
A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS …
- CVE-2025-50567CRITICALCVSS 10.0EG 10.02025-08-19
Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interpolate SQL query parameters. This leads to injection of user-control…
- CVE-2012-10047CRITICALCVSS 10.0EG 10.02025-08-08
Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is not properly sanitized, allowing attackers to inject arbitrary SQL …
- CVE-2025-54119CRITICALCVSS 10.0EG 10.02025-08-05
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements …
- CVE-2014-125123CRITICALCVSS 10.0EG 10.02025-07-31
An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) prior to version 6.1.12. The flaw resides in the login-name parameter passed to lbin/webcommand.php, which fails to proper…
- CVE-2014-125115CRITICALCVSS 10.0EG 10.02025-07-25
An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly sanitize user input in the loginhash_data parameter, allowing attackers to extract administra…
- CVE-2025-4285CRITICALCVSS 10.0EG 10.02025-07-22
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Information Technologies Agentis allows SQL Injection. This issue affects Agentis: before 4.32.
- CVE-2025-34112CRITICALCVSS 10.0EG 10.02025-07-15
An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited t…
- CVE-2025-46337CRITICALCVSS 10.0EG 10.02025-05-01
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when …
- CVE-2025-26852CRITICALCVSS 10.0EG 10.02025-03-20
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.
- CVE-2025-22954CRITICALCVSS 10.0EG 10.02025-03-12
GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter.
- CVE-2024-13152CRITICALCVSS 10.0EG 10.02025-02-14
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection. This issue affects Mobuy Online Machinery Monitoring Panel: b…
- CVE-2024-55971CRITICALCVSS 10.0EG 10.02025-01-23
SQL Injection vulnerability in the default configuration of the Logitime WebClock application <= 5.43.0 allows an unauthenticated user to run arbitrary code on the backend database server.
- CVE-2024-54261CRITICALCVSS 10.0EG 10.02024-12-13
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK Digital Agency LLC TAX SERVICE Electronic HDM virtual-hdm-for-taxservice-am allows SQL Injection.This issue affects TAX SERVICE Electr…
- CVE-2024-8529CRITICALCVSS 10.0EG 10.02024-09-12
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insu…
- CVE-2024-8522CRITICALCVSS 10.0EG 10.02024-09-12
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insuff…
- CVE-2024-6795CRITICALCVSS 10.0EG 10.02024-09-09
In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database. An attacker could have submitted a c…
- CVE-2024-43918CRITICALCVSS 10.0EG 10.02024-08-29
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WBW Product Table PRO allows SQL Injection.This issue affects WBW Product Table PRO: from n/a through 1.9.4.
- CVE-2024-7854CRITICALCVSS 10.0EG 10.02024-08-21
The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to insufficient escaping on the user supplied parameter 'dbid' and lack of sufficient preparation on the existing SQL query. …
- CVE-2024-39911CRITICALCVSS 10.0EG 10.02024-07-18
1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been addressed in version 1.10.12-lts. Users are advised to upgrade. There are no known worka…
- CVE-2024-37112CRITICALCVSS 10.0EG 10.02024-07-09
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.
- CVE-2024-1839CRITICALCVSS 10.0EG 10.02024-06-26
Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious code, exfiltrate data, or manipulate the database.
- CVE-2024-3605CRITICALCVSS 10.0EG 10.02024-06-20
The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the use…
- CVE-2024-3922CRITICALCVSS 10.0EG 10.02024-06-13
The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e…
- CVE-2024-36412CRITICALCVSS 10.0EG 10.02024-06-10
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain…
- CVE-2024-3820CRITICALCVSS 10.0EG 10.02024-06-01
The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL Injection via the 'id_key' parameter of the wdt_delete_table_row AJAX action in all versions up to, and including, 6.…
- CVE-2024-0851CRITICALCVSS 10.0EG 10.02024-05-27
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Grup Arge Energy and Control Systems Smartpower allows SQL Injection. This issue affects Smartpower: through V24.05.27.
- CVE-2024-32888CRITICALCVSS 10.0EG 10.02024-05-15
The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28,…
- CVE-2024-27298CRITICALCVSS 10.0EG 10.02024-03-01
parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The vulnerability has been fixed in 6.5.0 and 7.0.0-alpha.20.
- CVE-2024-1597CRITICALCVSS 10.0EG 10.02024-02-19
pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded …
- CVE-2023-25960CRITICALCVSS 10.0EG 10.02023-11-03
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – Global Dropshipping zendrop-dropshipping-and-fulfillment allows SQL Injection.This issue affects Zendrop – Global D…
- CVE-2023-34976CRITICALCVSS 10.0EG 10.02023-10-13
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following vers…
- CVE-2023-39344CRITICALCVSS 10.0EG 10.02023-08-04
social-media-skeleton is an uncompleted social media project. A SQL injection vulnerability in the project allows UNION based injections, which indirectly leads to remote code execution. Commit 3cabdd35c3d874608883c9eaf9bf69b2014d25c1 cont…
- CVE-2023-22583CRITICALCVSS 10.0EG 10.02023-06-11
The Danfoss AK-EM100 web forms allow for SQL injection in the login forms.
- CVE-2023-28849CRITICALCVSS 10.0EG 10.02023-04-05
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be…
- CVE-2023-25813CRITICALCVSS 10.0EG 10.02023-02-22
Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed through replacements are not properly escaped which can lead to arbitrary SQL injection depend…
- CVE-2022-45822CRITICALCVSS 10.0EG 10.02022-12-05
Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.
- CVE-2022-42497CRITICALCVSS 10.0EG 10.02022-11-18
Arbitrary Code Execution vulnerability in Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.
- CVE-2022-2422CRITICALCVSS 10.0EG 10.02022-10-26
Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used.
- CVE-2022-2421CRITICALCVSS 10.0EG 10.02022-10-26
Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.
- CVE-2022-29822CRITICALCVSS 10.0EG 10.02022-10-26
Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection
- CVE-2022-26959CRITICALCVSS 10.0EG 10.02022-09-16
There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Por…
- CVE-2022-35947CRITICALCVSS 10.0EG 10.02022-09-14
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions have been found to be vuln…
- CVE-2021-27472CRITICALCVSS 10.0EG 10.02022-03-23
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
- CVE-2021-27468CRITICALCVSS 10.0EG 10.02022-03-23
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statemen…
- CVE-2021-27464CRITICALCVSS 10.0EG 10.02022-03-23
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL stat…
- CVE-2022-21643CRITICALCVSS 10.0EG 10.02022-01-04
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used direc…
- CVE-2021-40850CRITICALCVSS 10.0EG 10.02021-12-17
TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.
- CVE-2021-42313CRITICALCVSS 10.0EG 10.02021-12-15
Microsoft Defender for IoT Remote Code Execution Vulnerability
Map vulnerabilities like CWE-89 to your infrastructure
EchelonGraph correlates every CVE — across CWE-89 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →