CWE-89— SQL Injection
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.— MITRE CWE catalog
21,099 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-89page 3 of 422
- CVE-2021-42311CRITICALCVSS 10.0EG 10.02021-12-15
Microsoft Defender for IoT Remote Code Execution Vulnerability
- CVE-2020-29493CRITICALCVSS 10.0EG 10.02021-01-14
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands …
- CVE-2020-7356CRITICALCVSS 10.0EG 10.02020-08-06
CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries…
- CVE-2020-8967CRITICALCVSS 10.0EG 10.02020-06-01
There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php files of GESIO ERP. GESIO ERP all versions prior to 11.2 allows malicious users to retrieve all database information.
- CVE-2020-3936CRITICALCVSS 10.0EG 10.02020-03-27
UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.
- CVE-2019-5151CRITICALCVSS 10.0EG 10.02019-10-31
An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, w…
- CVE-2019-7003CRITICALCVSS 10.0EG 10.02019-07-11
A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions…
- CVE-2018-12464CRITICALCVSS 10.0EG 10.02018-06-29
A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be explo…
- CVE-2016-8027CRITICALCVSS 10.0EG 10.02017-03-14
SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the databa…
- CVE-2015-8974CRITICALCVSS 10.0EG 10.02017-01-31
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL co…
- CVE-2025-52694CRITICALCVSS 9.8EG 10.02026-01-12
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidenti…
- CVE-2025-63531CRITICALCVSS 9.8EG 10.02025-12-01
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQ…
- CVE-2024-12909CRITICALCVSS 9.8EG 10.02025-03-20
A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `database_agent`. This vulnerability can be exploited by an attack…
- CVE-2023-5046CRITICALCVSS 9.8EG 10.02023-10-12
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Procost allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Procost: before 1390.
- CVE-2023-5045CRITICALCVSS 9.8EG 10.02023-10-12
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Kayisi allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Kayisi: before 1286.
- CVE-2023-4309CRITICALCVSS 9.8EG 10.02023-10-10
Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the …
- CVE-2023-1547CRITICALCVSS 9.8EG 10.02023-07-13
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Elra Parkmatik allows SQL Injection through SOAP Parameter Tampering, Command Line Execution through SQL Injection. This issue affects P…
- CVE-2023-2851CRITICALCVSS 9.8EG 10.02023-05-25
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron allows Command Line Execution through SQL Injection, SQL Injection. This issue affects all versions of the sofware al…
- CVE-2014-3828HIGHCVSS v2 10.0EG 10.02014-10-23
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attackers to execute arbitrary SQL commands via (1) the index_id parameter to views/graphs/common/makeXM…
- CVE-2014-5503HIGHCVSS v2 10.0EG 10.02014-10-07
SQL injection vulnerability in the Guest Login Portal in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary SQL commands via the add_guest_user opcode.
- CVE-2011-1653HIGHCVSS v2 10.0EG 10.02011-04-18
Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attackers to execute arbitrary SQL commands via vectors involving the (1) UnAssignFunctionalRoles, (2) …
- CVE-2003-1573HIGHCVSS v2 10.0EG 10.02009-06-01
The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, relat…
- CVE-2009-1034HIGHCVSS v2 10.0EG 10.02009-03-20
SQL injection vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via values in the URI.
- CVE-2008-5649HIGHCVSS v2 10.0EG 10.02008-12-17
SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via the username parameter.
- CVE-2008-0735HIGHCVSS v2 10.0EG 10.02008-02-13
SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter.
- CVE-2007-6491HIGHCVSS v2 10.0EG 10.02007-12-20
Multiple SQL injection vulnerabilities in Kvaliitti WebDoc 3.0 CMS allow remote attackers to execute arbitrary SQL commands via (1) the cat_id parameter to categories.asp; and probably (2) the document_id parameter to categories.asp, and t…
- CVE-2007-6172HIGHCVSS v2 10.0EG 10.02007-11-30
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewimage.php and (2) comments.php.
- CVE-2007-5452HIGHCVSS v2 10.0EG 10.02007-10-14
Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) ip or (2) t parameter.
- CVE-2007-5372HIGHCVSS v2 10.0EG 10.02007-10-11
Multiple SQL injection vulnerabilities in (a) LedgerSMB 1.0.0 through 1.2.7 and (b) DWS Systems SQL-Ledger 2.x allow remote attackers to execute arbitrary SQL commands via (1) the invoice quantity field or (2) the sort field.
- CVE-2026-79798CRITICALCVSS 9.9EG 9.92026-10-06
SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Succ…
- CVE-2026-75682CRITICALCVSS 9.9EG 9.92026-09-22
Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker …
- CVE-2026-82010CRITICALCVSS 9.9EG 9.92026-09-22
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privi…
- CVE-2026-61781CRITICALCVSS 9.9EG 9.92026-09-18
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynami…
- CVE-2026-84064CRITICALCVSS 9.9EG 9.92026-09-18
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
- CVE-2026-79303CRITICALCVSS 9.9EG 9.92026-09-15
kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without the required data validation and without using parameterized statements or stored procedures.
- CVE-2026-67401CRITICALCVSS 9.9EG 9.92026-09-09
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
- CVE-2026-78623CRITICALCVSS 9.9EG 9.92026-09-08
The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to pr…
- CVE-2026-55634CRITICALCVSS 9.9EG 9.92026-08-28
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject …
- CVE-2026-68782CRITICALCVSS 9.9EG 9.92026-08-20
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68789CRITICALCVSS 9.9EG 9.92026-08-20
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
- CVE-2026-51366CRITICALCVSS 9.9EG 9.92026-08-19
SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter
- CVE-2026-48326CRITICALCVSS 9.9EG 9.92026-08-03
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privi…
- CVE-2026-58046CRITICALCVSS 9.9EG 9.92026-07-30
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.
- CVE-2026-63234CRITICALCVSS 9.9EG 9.92026-07-29
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessibl…
- CVE-2026-63233CRITICALCVSS 9.9EG 9.92026-07-29
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly access…
- CVE-2026-63232CRITICALCVSS 9.9EG 9.92026-07-29
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessi…
- CVE-2026-45262CRITICALCVSS 9.9EG 9.92026-07-14
FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn` ## Summary > **Live PoC verified 2026-04-30** against a stock FacturaScripts master at `127.0.0.1:80…
- CVE-2026-61667CRITICALCVSS 9.9EG 9.92026-07-13
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled datase…
- CVE-2026-50747CRITICALCVSS 9.9EG 9.92026-07-02
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.
- CVE-2026-52785CRITICALCVSS 9.9EG 9.92026-06-26
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work-package attributes…
Map vulnerabilities like CWE-89 to your infrastructure
EchelonGraph correlates every CVE — across CWE-89 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →