CWE-89— SQL Injection
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.— MITRE CWE catalog
21,099 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-89page 6 of 422
- CVE-2026-73663CRITICALCVSS 9.8EG 9.82026-08-13
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without esc…
- CVE-2026-16961CRITICALCVSS 9.8EG 9.82026-08-13
IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
- CVE-2026-17111CRITICALCVSS 9.8EG 9.82026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
- CVE-2026-73211CRITICALCVSS 9.8EG 9.82026-08-11
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to r…
- CVE-2026-72599CRITICALCVSS 9.8EG 9.82026-08-11
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a SQL WHERE clause. An unauthenticated a…
- CVE-2026-72550CRITICALCVSS 9.8EG 9.82026-08-11
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. The parameter is concatenated unescaped into a SHOW …
- CVE-2026-19425CRITICALCVSS 9.8EG 9.82026-08-11
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
- CVE-2026-63106CRITICALCVSS 9.8EG 9.82026-08-10
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterizati…
- CVE-2026-72565CRITICALCVSS 9.8EG 9.82026-08-10
A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator.
- CVE-2026-32227CRITICALCVSS 9.8EG 9.82026-08-10
SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue.
- CVE-2026-5134CRITICALCVSS 9.8EG 9.82026-08-06
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was …
- CVE-2026-67689CRITICALCVSS 9.8EG 9.82026-08-06
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints
- CVE-2026-71248CRITICALCVSS 9.8EG 9.82026-08-05
Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * from user where email = '' and password = ''", with no escaping or parameterization, allowi…
- CVE-2026-71237CRITICALCVSS 9.8EG 9.82026-08-05
Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query("select * from userlists where username='' and passwo…
- CVE-2026-71231CRITICALCVSS 9.8EG 9.82026-08-05
IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-sa…
- CVE-2026-71207CRITICALCVSS 9.8EG 9.82026-08-05
The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escap…
- CVE-2026-69240CRITICALCVSS 9.8EG 9.82026-08-03
Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE…
- CVE-2026-51775CRITICALCVSS 9.8EG 9.82026-08-03
SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component
- CVE-2026-65321CRITICALCVSS 9.8EG 9.82026-08-02
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS stateme…
- CVE-2025-69946CRITICALCVSS 9.8EG 9.82026-07-31
SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id.
- CVE-2025-69948CRITICALCVSS 9.8EG 9.82026-07-31
SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.
- CVE-2026-4978CRITICALCVSS 9.8EG 9.82026-07-30
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects Traffic Analysis System: from 30 before 34.
- CVE-2026-17543CRITICALCVSS 9.8EG 9.82026-07-30
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
- CVE-2025-65336CRITICALCVSS 9.8EG 9.82026-07-30
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.
- CVE-2025-69930CRITICALCVSS 9.8EG 9.82026-07-30
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
- CVE-2025-69931CRITICALCVSS 9.8EG 9.82026-07-30
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.
- CVE-2025-69933CRITICALCVSS 9.8EG 9.82026-07-30
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
- CVE-2025-69934CRITICALCVSS 9.8EG 9.82026-07-30
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
- CVE-2025-69935CRITICALCVSS 9.8EG 9.82026-07-30
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
- CVE-2025-69936CRITICALCVSS 9.8EG 9.82026-07-30
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
- CVE-2025-69937CRITICALCVSS 9.8EG 9.82026-07-30
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
- CVE-2025-69938CRITICALCVSS 9.8EG 9.82026-07-30
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
- CVE-2025-69941CRITICALCVSS 9.8EG 9.82026-07-30
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.
- CVE-2025-69947CRITICALCVSS 9.8EG 9.82026-07-30
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
- CVE-2026-65890CRITICALCVSS 9.8EG 9.82026-07-29
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
- CVE-2025-65340CRITICALCVSS 9.8EG 9.82026-07-29
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.
- CVE-2025-67403CRITICALCVSS 9.8EG 9.82026-07-29
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.
- CVE-2025-67404CRITICALCVSS 9.8EG 9.82026-07-29
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.
- CVE-2025-69942CRITICALCVSS 9.8EG 9.82026-07-29
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
- CVE-2025-69943CRITICALCVSS 9.8EG 9.82026-07-29
kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
- CVE-2026-54658CRITICALCVSS 9.8EG 9.82026-07-28
Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled que…
- CVE-2026-16462CRITICALCVSS 9.8EG 9.82026-07-28
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
- CVE-2026-63359CRITICALCVSS 9.8EG 9.82026-07-23
The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other us…
- CVE-2026-2395CRITICALCVSS 9.8EG 9.82026-07-22
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.1.3 before…
- CVE-2016-20096CRITICALCVSS 9.8EG 9.82026-07-21
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login end…
- CVE-2026-1617CRITICALCVSS 9.8EG 9.82026-07-21
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This issue affects Turkhotspot 5651 Loglama: from 5.…
- CVE-2026-52469CRITICALCVSS 9.8EG 9.82026-07-21
SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file
- CVE-2026-52470CRITICALCVSS 9.8EG 9.82026-07-21
SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file
- CVE-2026-52472CRITICALCVSS 9.8EG 9.82026-07-21
SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file
- CVE-2026-57308CRITICALCVSS 9.8EG 9.82026-07-20
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsa…
Map vulnerabilities like CWE-89 to your infrastructure
EchelonGraph correlates every CVE — across CWE-89 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →