Skip to content
Noroxi

CWE-89 · 17,346 records

SQL injection

Why does it happen?

The query text is built by concatenating user input. The database cannot tell where the data ends and the command begins.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

ts
const owner = req.query.owner;const rows = await db.query(  "SELECT * FROM files WHERE owner = '" + owner + "'");

Fixed

ts
const owner = req.query.owner;const rows = await db.query(  "SELECT * FROM files WHERE owner = $1",  [owner]);

How to prevent it

  1. 01Use parameterized queries or a trusted ORM for every query.
  2. 02Grant the database account privileges only on the tables it needs.
  3. 03Restrict dynamic column or sort names with an allowlist.

CVEs in this class

10,000 records

  • In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    progress · moveit cloudJun 2, 2023

  • An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet For

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    fortinet · fortiwebJul 17, 2025

  • A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    fortinet · forticlient enterprise management serverMar 12, 2024

  • Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    citrix · netscaler sd-wanJul 16, 2019

  • An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may a

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    fortinet · forticlientemsFeb 6, 2026

  • WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 93%

    progress · whatsup goldAug 29, 2024

  • Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure

    CriticalCVSS 9.2KEVWeaponizedEPSS 100%

    paloaltonetworks · expeditionOct 9, 2024

  • FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    thedaylightstudio · fuel cmsAug 13, 2020

  • FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE

    CriticalCVSS 10.0KEVWeaponizedEPSS 85%

    sangoma · freepbxAug 28, 2025

  • An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the sam

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    ivanti · endpoint managerMay 31, 2024

  • ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct ac

    CriticalCVSS 9.8KEVWeaponizedEPSS 87%

    connectwise · manageditsyncFeb 5, 2019

  • The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request.

    CriticalCVSS 9.8KEVWeaponizedEPSS 84%

    grandstream · ucm6200 firmwareMar 23, 2020

  • Microsoft Configuration Manager Remote Code Execution Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 81%

    microsoft · configuration manager 2403Oct 8, 2024

  • BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in th

    CriticalCVSS 9.8KEVWeaponizedEPSS 74%

    bqe · billquick web suiteOct 22, 2021

  • A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an i

    CriticalCVSS 9.8KEVWeaponizedEPSS 73%

    schneider-electric · u.motion builderMay 22, 2019

  • Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources.

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    sonicwall · sma 100 firmwareDec 17, 2019

  • SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands v

    CriticalCVSS 9.8KEVWeaponizedEPSS 72%

    sap · netweaver application server javaFeb 16, 2016

  • Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

    CriticalCVSS 9.8KEVWeaponizedEPSS 70%

    roundcube · webmailNov 19, 2021

  • A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild

    CriticalCVSS 9.8KEVWeaponizedEPSS 42%

    sophos · sfosApr 27, 2020

  • A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access

    CriticalCVSS 9.8KEVWeaponizedEPSS 40%

    sonicwall · sma 100 firmwareFeb 4, 2021

  • CVE-2021-20028
    78This week

    Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, s

    CriticalCVSS 9.8KEVWeaponizedEPSS 30%

    sonicwall · sma 210 firmwareAug 4, 2021

  • CVE-2025-25181
    77This week

    A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL

    HighCVSS 7.5KEVWeaponizedEPSS 57%

    advantive · veracoreFeb 3, 2025

  • CVE-2026-76461
    77This week

    Cisco Secure Email Gateway SQL Injection Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 28%

    cisco · asyncosSep 14, 2026

  • CVE-2026-72898
    76This week

    Metabase SQL injection via password reset endpoint

    CriticalCVSS 10.0KEVWeaponizedEPSS 19%

    metabase · metabaseAug 10, 2026

  • CVE-2026-9082
    74This week

    Drupal core - Highly critical - SQL injection - SA-CORE-2026-004

    CriticalCVSS 9.8KEVWeaponizedEPSS 16%

    drupal · drupalMay 20, 2026

All vulnerability classes