CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability was identified in 9786 phpok3w up to 901d96a06809fb28b17f3a4362c59e70411c933c. Impacted is an unknown fu
A vulnerability has been found in itsourcecode Online Cake Ordering System 1.0. The impacted element is an unknown funct
A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown function of the file
A vulnerability was determined in itsourcecode Online Cake Ordering System 1.0. This impacts an unknown function of the
A vulnerability was identified in itsourcecode Student Management System 1.0. Affected is an unknown function of the fil
A security flaw has been discovered in code-projects Refugee Food Management System 1.0. The impacted element is an unkn
A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown function of
A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This impacts an unknown
A vulnerability was detected in code-projects Refugee Food Management System 1.0. Affected is an unknown function of the
A flaw has been found in code-projects Refugee Food Management System 1.0. Affected by this vulnerability is an unknown
A vulnerability has been found in code-projects Refugee Food Management System 1.0. Affected by this issue is some unkno
A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functi
A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file logi
A weakness has been identified in code-projects College Notes Uploading System 1.0. This issue affects some unknown proc
A flaw has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /admin/a
A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file
A security flaw has been discovered in code-projects Refugee Food Management System 1.0. Affected by this issue is some
A flaw has been found in code-projects Simple Stock System 1.0. This affects an unknown function of the file /market/log
A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected is an unknown function of the file /admin/logi
A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is the function edit_admin_query of
A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the
Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in var
SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allow
Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php.
The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL state
A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote
A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attacke
A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, whi
A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, whi
A SQL Injection vulnerability was found in /admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remo
A SQL Injection vulnerability was found in /admin/manage-propertytype.php in PHPGurukul Land Record System v1.0, which a
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploit
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploit
A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploi
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file
SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_re
A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (
yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticate
horvey Library-Manager v1.0 is vulnerable to SQL Injection in Admin/Controller/BookController.class.php.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Cli
In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, a
FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Bool
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-
A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing
owl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order.
The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statem
The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL stat
The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started