CWE-89 · 17,346 records
SQL injection
Why does it happen?
The query text is built by concatenating user input. The database cannot tell where the data ends and the command begins.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
const owner = req.query.owner;const rows = await db.query( "SELECT * FROM files WHERE owner = '" + owner + "'");Fixed
const owner = req.query.owner;const rows = await db.query( "SELECT * FROM files WHERE owner = $1", [owner]);How to prevent it
- 01Use parameterized queries or a trusted ORM for every query.
- 02Grant the database account privileges only on the tables it needs.
- 03Restrict dynamic column or sort names with an allowlist.
CVEs in this class
10,000 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2023-34362Weaponized | In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL progress · moveit cloud · CWE-89 | Critical9.8 | KEV | 99.9% | Jun 2, 2023 |
99Now | CVE-2025-25257Weaponized | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet Forfortinet · fortiweb · CWE-89 | Critical9.8 | KEV | 99.8% | Jul 17, 2025 |
99Now | CVE-2023-48788Weaponized | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.fortinet · forticlient enterprise management server · CWE-89 | Critical9.8 | KEV | 98.4% | Mar 12, 2024 |
97Now | CVE-2019-12989Weaponized | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.citrix · netscaler sd-wan · CWE-89 | Critical9.8 | KEV | 95.0% | Jul 16, 2019 |
97Now | CVE-2026-21643Weaponized | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may afortinet · forticlientems · CWE-89 | Critical9.8 | KEV | 93.7% | Feb 6, 2026 |
97Now | CVE-2024-6670Weaponized | WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerabilityprogress · whatsup gold · CWE-89 | Critical9.8 | KEV | 93.0% | Aug 29, 2024 |
96Now | CVE-2024-9465Weaponized | Expedition: SQL Injection Leads to Firewall Admin Credential Disclosurepaloaltonetworks · expedition · CWE-89 | Critical9.2 | KEV | 99.6% | Oct 9, 2024 |
96Now | CVE-2020-17463Weaponized | FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.thedaylightstudio · fuel cms · CWE-89 | Critical9.8 | KEV | 89.7% | Aug 13, 2020 |
96Now | CVE-2025-57819Weaponized | FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCEsangoma · freepbx · CWE-89 | Critical10.0 | KEV | 85.5% | Aug 28, 2025 |
95Now | CVE-2024-29824Weaponized | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the samivanti · endpoint manager · CWE-89 | High8.8 | KEV | 99.9% | May 31, 2024 |
95Now | CVE-2017-18362Weaponized | ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct acconnectwise · manageditsync · CWE-89 | Critical9.8 | KEV | 86.8% | Feb 5, 2019 |
94Now | CVE-2020-5722Weaponized | The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request.grandstream · ucm6200 firmware · CWE-89 | Critical9.8 | KEV | 84.4% | Mar 23, 2020 |
93Now | CVE-2024-43468Weaponized | Microsoft Configuration Manager Remote Code Execution Vulnerabilitymicrosoft · configuration manager 2403 · CWE-89 | Critical9.8 | KEV | 80.9% | Oct 8, 2024 |
91Now | CVE-2021-42258Weaponized | BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in thbqe · billquick web suite · CWE-89 | Critical9.8 | KEV | 74.4% | Oct 22, 2021 |
91Now | CVE-2018-7841Weaponized | A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an ischneider-electric · u.motion builder · CWE-89 | Critical9.8 | KEV | 72.7% | May 22, 2019 |
90Now | CVE-2019-7481Weaponized | Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources.sonicwall · sma 100 firmware · CWE-89 | High7.5 | KEV | 99.9% | Dec 17, 2019 |
90Now | CVE-2016-2386Weaponized | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands vsap · netweaver application server java · CWE-89 | Critical9.8 | KEV | 71.5% | Feb 16, 2016 |
90Now | CVE-2021-44026Weaponized | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.roundcube · webmail · CWE-89 | Critical9.8 | KEV | 69.9% | Nov 19, 2021 |
82Now | CVE-2020-12271Weaponized | A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wildsophos · sfos · CWE-89 | Critical9.8 | KEV | 42.4% | Apr 27, 2020 |
81Now | CVE-2021-20016Weaponized | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to accesssonicwall · sma 100 firmware · CWE-89 | Critical9.8 | KEV | 40.0% | Feb 4, 2021 |
78This week | CVE-2021-20028Weaponized | Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, ssonicwall · sma 210 firmware · CWE-89 | Critical9.8 | KEV | 30.1% | Aug 4, 2021 |
77This week | CVE-2025-25181Weaponized | A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL advantive · veracore · CWE-89 | High7.5 | KEV | 57.3% | Feb 3, 2025 |
77This week | CVE-2026-76461Weaponized | Cisco Secure Email Gateway SQL Injection Vulnerabilitycisco · asyncos · CWE-89 | Critical9.8 | KEV | 28.3% | Sep 14, 2026 |
76This week | CVE-2026-72898Weaponized | Metabase SQL injection via password reset endpointmetabase · metabase · CWE-89 | Critical10.0 | KEV | 19.0% | Aug 10, 2026 |
74This week | CVE-2026-9082Weaponized | Drupal core - Highly critical - SQL injection - SA-CORE-2026-004drupal · drupal · CWE-89 | Critical9.8 | KEV | 15.7% | May 20, 2026 |
- CVE-2023-3436299Now
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL
CriticalCVSS 9.8KEVWeaponizedEPSS 100%progress · moveit cloudJun 2, 2023
- CVE-2025-2525799Now
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet For
CriticalCVSS 9.8KEVWeaponizedEPSS 100%fortinet · fortiwebJul 17, 2025
- CVE-2023-4878899Now
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.
CriticalCVSS 9.8KEVWeaponizedEPSS 98%fortinet · forticlient enterprise management serverMar 12, 2024
- CVE-2019-1298997Now
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
CriticalCVSS 9.8KEVWeaponizedEPSS 95%citrix · netscaler sd-wanJul 16, 2019
- CVE-2026-2164397Now
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may a
CriticalCVSS 9.8KEVWeaponizedEPSS 94%fortinet · forticlientemsFeb 6, 2026
- CVE-2024-667097Now
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 93%progress · whatsup goldAug 29, 2024
- CVE-2024-946596Now
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
CriticalCVSS 9.2KEVWeaponizedEPSS 100%paloaltonetworks · expeditionOct 9, 2024
- CVE-2020-1746396Now
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
CriticalCVSS 9.8KEVWeaponizedEPSS 90%thedaylightstudio · fuel cmsAug 13, 2020
- CVE-2025-5781996Now
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
CriticalCVSS 10.0KEVWeaponizedEPSS 85%sangoma · freepbxAug 28, 2025
- CVE-2024-2982495Now
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the sam
HighCVSS 8.8KEVWeaponizedEPSS 100%ivanti · endpoint managerMay 31, 2024
- CVE-2017-1836295Now
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct ac
CriticalCVSS 9.8KEVWeaponizedEPSS 87%connectwise · manageditsyncFeb 5, 2019
- CVE-2020-572294Now
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request.
CriticalCVSS 9.8KEVWeaponizedEPSS 84%grandstream · ucm6200 firmwareMar 23, 2020
- CVE-2024-4346893Now
Microsoft Configuration Manager Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 81%microsoft · configuration manager 2403Oct 8, 2024
- CVE-2021-4225891Now
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in th
CriticalCVSS 9.8KEVWeaponizedEPSS 74%bqe · billquick web suiteOct 22, 2021
- CVE-2018-784191Now
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an i
CriticalCVSS 9.8KEVWeaponizedEPSS 73%schneider-electric · u.motion builderMay 22, 2019
- CVE-2019-748190Now
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources.
HighCVSS 7.5KEVWeaponizedEPSS 100%sonicwall · sma 100 firmwareDec 17, 2019
- CVE-2016-238690Now
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands v
CriticalCVSS 9.8KEVWeaponizedEPSS 72%sap · netweaver application server javaFeb 16, 2016
- CVE-2021-4402690Now
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
CriticalCVSS 9.8KEVWeaponizedEPSS 70%roundcube · webmailNov 19, 2021
- CVE-2020-1227182Now
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild
CriticalCVSS 9.8KEVWeaponizedEPSS 42%sophos · sfosApr 27, 2020
- CVE-2021-2001681Now
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access
CriticalCVSS 9.8KEVWeaponizedEPSS 40%sonicwall · sma 100 firmwareFeb 4, 2021
- CVE-2021-2002878This week
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, s
CriticalCVSS 9.8KEVWeaponizedEPSS 30%sonicwall · sma 210 firmwareAug 4, 2021
- CVE-2025-2518177This week
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL
HighCVSS 7.5KEVWeaponizedEPSS 57%advantive · veracoreFeb 3, 2025
- CVE-2026-7646177This week
Cisco Secure Email Gateway SQL Injection Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 28%cisco · asyncosSep 14, 2026
- CVE-2026-7289876This week
Metabase SQL injection via password reset endpoint
CriticalCVSS 10.0KEVWeaponizedEPSS 19%metabase · metabaseAug 10, 2026
- CVE-2026-908274This week
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
CriticalCVSS 9.8KEVWeaponizedEPSS 16%drupal · drupalMay 20, 2026