CWE-89— SQL Injection
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.— MITRE CWE catalog
21,099 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-89page 4 of 422
- CVE-2026-54310CRITICALCVSS 9.9EG 9.92026-06-16
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node's allow…
- CVE-2026-46624CRITICALCVSS 9.9EG 9.92026-05-26
Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. If Postgres user is a super user then any…
- CVE-2026-41478CRITICALCVSS 9.9EG 9.92026-04-24
Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcorn’s mobile-sync routes allows any authenticated low-privilege user with read a…
- CVE-2026-27681CRITICALCVSS 9.9EG 9.92026-04-14
Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact…
- CVE-2026-23696CRITICALCVSS 9.9EG 9.92026-04-07
Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use …
- CVE-2026-32306CRITICALCVSS 9.9EG 9.92026-03-13
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregationType, aggregateColumnName, and aggregationTimestampColumnName parameters and interpolat…
- CVE-2026-21708CRITICALCVSS 9.9EG 9.92026-03-12
A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.
- CVE-2025-11165CRITICALCVSS 9.9EG 9.92026-02-24
A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to bypass class and package restrictions enforced by SecureUberspectorImpl. By dynamically mo…
- CVE-2026-0501CRITICALCVSS 9.9EG 9.92026-01-13
Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high i…
- CVE-2025-55343CRITICALCVSS 9.9EG 9.92025-11-05
Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi, busqueda/busqueda.php txt_usua_codi, anexos_lista.php radi_temp, Administracion/listas/formArea_ajax.php codD…
- CVE-2025-24290CRITICALCVSS 9.9EG 9.92025-06-29
Multiple Authenticated SQL Injection vulnerabilities found in UISP Application (Version 2.4.206 and earlier) could allow a malicious actor with low privileges to escalate privileges.
- CVE-2024-8950CRITICALCVSS 9.9EG 9.92024-12-25
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics Piramit Automation allows Blind SQL Injection. This issue affects Piramit Automation: before 27.09.2024.
- CVE-2024-45387CRITICALCVSS 9.9EG 9.92024-12-23
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sen…
- CVE-2024-42327CRITICALCVSS 9.9EG 9.92024-11-27
A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is …
- CVE-2024-51482CRITICALCVSS 9.9EG 9.92024-10-31
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.
- CVE-2024-8621CRITICALCVSS 9.9EG 9.92024-09-25
The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, and including, 2024.08.26 due to insufficient escaping on the user supplied parame…
- CVE-2024-8436CRITICALCVSS 9.9EG 9.92024-09-25
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5 due to insufficient escaping on the u…
- CVE-2024-8624CRITICALCVSS 9.9EG 9.92024-09-24
The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attribute of the 'mdf_select_title' shortcode in all versions up to, and including, 1.3.3.3 due to insufficient escaping on…
- CVE-2024-4872CRITICALCVSS 9.9EG 9.92024-08-27
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an …
- CVE-2024-37906CRITICALCVSS 9.9EG 9.92024-07-29
Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.9, there is an SQL Injection in the `/adm_program/modules/ecards/ecard_send.php` source file of the Admidio Appli…
- CVE-2024-3604CRITICALCVSS 9.9EG 9.92024-07-09
The OSM – OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the 'osm_map_v3' shortcode in all versions up to, and including, 6.0.3 due to insufficient escaping on the user supplied par…
- CVE-2024-3549CRITICALCVSS 9.9EG 9.92024-06-11
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied param…
- CVE-2024-3592CRITICALCVSS 9.9EG 9.92024-06-07
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on …
- CVE-2024-36393CRITICALCVSS 9.9EG 9.92024-06-06
SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- CVE-2024-3200CRITICALCVSS 9.9EG 9.92024-06-01
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and including, 2.3.3 due to insufficient escaping on the user supplied parameter and lack of suf…
- CVE-2024-3342CRITICALCVSS 9.9EG 9.92024-04-27
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all versions up to, and including, 2.4.11 due to insufficient escaping on the u…
- CVE-2024-23538CRITICALCVSS 9.9EG 9.92024-03-29
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the is…
- CVE-2024-27956CRITICALCVSS 9.9EG 9.92024-03-21
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.
- CVE-2021-43609CRITICALCVSS 9.9EG 9.92023-11-09
An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute …
- CVE-2023-36529CRITICALCVSS 9.9EG 9.92023-11-03
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issue affects Houzez - Real Estate WordPress Theme: from n/a th…
- CVE-2022-36276CRITICALCVSS 9.9EG 9.92023-10-04
TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerability might allow a remote attacker to directly interact with the database.
- CVE-2023-30839CRITICALCVSS 9.9EG 9.92023-04-25
PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.…
- CVE-2022-45808CRITICALCVSS 9.9EG 9.92023-01-26
SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
- CVE-2023-0016CRITICALCVSS 9.9EG 9.92023-01-10
SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data …
- CVE-2022-44588CRITICALCVSS 9.9EG 9.92022-12-15
Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.
- CVE-2022-41272CRITICALCVSS 9.9EG 9.92022-12-13
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to…
- CVE-2021-43362CRITICALCVSS 9.9EG 9.92021-11-16
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1.
- CVE-2021-43361CRITICALCVSS 9.9EG 9.92021-11-16
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1.
- CVE-2021-42369CRITICALCVSS 9.9EG 9.92021-10-14
Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "Export to CSV" feature of the Contact Manager web GUI.
- CVE-2021-32590CRITICALCVSS 9.9EG 9.92021-08-04
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privi…
- CVE-2021-35049CRITICALCVSS 9.9EG 9.92021-06-25
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and …
- CVE-2021-23230CRITICALCVSS 9.9EG 9.92021-06-11
A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions…
- CVE-2021-21465CRITICALCVSS 9.9EG 9.92021-01-12
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly saniti…
- CVE-2019-5114CRITICALCVSS 9.9EG 9.92019-10-25
An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks …
- CVE-2018-20091CRITICALCVSS 9.9EG 9.92019-06-07
An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database contains user contact i…
- CVE-2019-7001CRITICALCVSS 9.9EG 9.92019-04-04
A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affected versions of IP Office Contact Center …
- CVE-2024-44761CRITICALCVSS 9.8EG 9.92024-08-28
An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.
- CVE-2023-45162CRITICALCVSS 9.8EG 9.92023-10-13
Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution. Application of the relevant hotfix remediates this issue. for v8.1.2 apply hotfix Q23166 for v8.4.1 apply hotfix Q23164 f…
- CVE-2023-4037CRITICALCVSS 5.5EG 9.92023-10-04
Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.
- CVE-2026-108474CRITICALCVSS 9.8EG 9.82026-10-09
In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions
Map vulnerabilities like CWE-89 to your infrastructure
EchelonGraph correlates every CVE — across CWE-89 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →