SQL Injection (CWE-89)
CWE-89 occurs when a product builds an SQL statement from outside input and does not neutralize SQL syntax within that input. The database then treats part of the input as query logic instead of plain data. SQLi is the common abbreviation.
About CWE-89
Because databases often hold sensitive data, disclosure is frequent. Attackers may also alter or delete records, log in as another user, change authorization data, and in some setups execute system commands.
Mitigations
- +Use prepared statements, parameterized queries or stored procedures that keep data apart from the query.
- +Avoid building and executing query strings dynamically inside stored procedures.
- +Use a vetted persistence framework that handles quoting and encoding correctly.
- +Run database connections with the least privilege required and use the strictest permissions on database objects.
- +Repeat client-side checks on the server.
Detection
Automated static analysis can often detect it using data flow analysis, and dynamic testing with diverse inputs such as fuzzing can also reveal it.
CWE-89 Vulnerabilities
20 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-9586 | Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB | Sangoma | 9.3 | 19.0% | KEV | 2026-07-17 |
| CVE-2026-72898 | Metabase SQL injection via password reset endpoint | Metabase | 10.0 | 19.0% | KEV | 2026-08-10 |
| CVE-2026-9082 | Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 | Drupal | 9.8 | 15.7% | KEV | 2026-05-20 |
| CVE-2026-42208 | LiteLLM: SQL injection in Proxy API key verification | BerriAI | 9.3 | 5.8% | KEV | 2026-05-08 |
| CVE-2026-21643 | Fortinet FortiClient EMS SQL Injection Vulnerability | Fortinet | 9.1 | 93.9% | KEV | 2026-02-06 |
| CVE-2024-43468 | Microsoft Configuration Manager Remote Code Execution Vulnerability | Microsoft | 9.8 | 81.0% | KEV | 2024-10-08 |
| CVE-2025-57819 | FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE | FreePBX | 10.0 | 86.3% | KEV | 2025-08-28 |
| CVE-2025-25257 | Fortinet FortiWeb SQL Injection Vulnerability | Fortinet | 9.6 | 99.8% | KEV | 2025-07-17 |
| CVE-2025-25181 | Advantive VeraCore SQL Injection Vulnerability | Advantive | 5.8 | 55.5% | KEV | 2025-02-03 |
| CVE-2024-9465 | Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure | Palo Alto Networks | 9.2 | 99.6% | KEV | 2024-10-09 |
| CVE-2024-9379 | Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability | Ivanti | 6.5 | 43.8% | KEV | 2024-10-08 |
| CVE-2024-6670 | WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability | Progress Software Corporation | 9.8 | 93.0% | KEV | 2024-08-29 |
| CVE-2023-48788 | Fortinet FortiClient EMS SQL Injection Vulnerability | Fortinet | 9.3 | 98.4% | KEV | 2024-03-12 |
| CVE-2023-46748 | BIG-IP Configuration utility authenticated SQL injection vulnerability | F5 | 8.8 | 4.5% | KEV | 2023-10-26 |
| CVE-2021-20028 | SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability | SonicWall | 9.8 | 30.1% | KEV | 2021-08-04 |
| CVE-2019-7481 | SonicWall SMA100 SQL Injection Vulnerability | SonicWall | 7.5 | 99.9% | KEV | 2019-12-17 |
| CVE-2021-20016 | SonicWall SSLVPN SMA100 SQL Injection Vulnerability | SonicWall | 9.8 | 40.0% | KEV | 2021-02-03 |
| CVE-2026-20947 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Microsoft | 8.8 | 18.8% | 2026-01-13 | |
| CVE-2026-23696 | Windmill < 1.603.3 File Ownership Handling SQLi RCE | Windmill Labs | 9.9 | 13.6% | 2026-04-07 | |
| CVE-2026-1207 | Potential SQL injection via raster lookups on PostGIS | djangoproject | 5.4 | 12.8% | 2026-02-03 |
Most Affected Vendors
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-89?→
CWE-89 is the MITRE entry for SQL injection, where input reaches an SQL command without neutralization and is interpreted as SQL.
What is the primary defense against SQL injection?→
MITRE recommends parameterization: prepared statements or parameterized queries that enforce separation between data and code, backed by least-privilege database accounts.
How many exploited vulnerabilities are classified as CWE-89?→
This database lists 20 CVE records mapped to CWE-89 by their CVE Numbering Authority. 17 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 5 to known ransomware campaigns. Examples include CVE-2026-9586, CVE-2026-72898, CVE-2026-9082.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.