CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL stateme
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP
SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenti
A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. T
SQL Injection affecting the Archiver role.
SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Tekno
User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutr
An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious
index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visibl
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu
Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerabilit
Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface
Nagios XI versions prior to 5.7.5 contain a SQL injection vulnerability in the SNMP Trap Interface edit page. Exploitati
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows
phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an authenticated SQL injection vulnerability in
i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL
i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL
i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL
ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL in
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiV
The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manage
ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in th
ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th
ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon
SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering th
A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index reposito
OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function l
SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensi
A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow a
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subjec
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), Query
The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System v
The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'ID' paramet
Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to err
Orangescrum 1.8.0 contains an authenticated SQL injection vulnerability that allows authorized users to manipulate datab
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak
An issue was discovered in simple-admin-core v1.2.0 thru v1.6.7. The /sys-api/role/update interface in the simple-admin-
SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.
CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter.
SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE:
Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated
A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potenti
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started