CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right t
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arb
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user
A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The
Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase ap
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-s
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a
Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXE
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backl
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authent
A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users wit
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API acc
OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in module
Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose de
Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership manag
Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authe
Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API
Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a
Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vu
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL inject
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL
SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary c
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-defi
SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive informat
An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit t
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon
ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind
indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId param
SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpo
BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites.
Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', a
phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.
Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate databa
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 3,170 CVE records associated with CWE-89 in our database. Of these, 483 are critical severity, 1577 are high severity, and 730 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started