CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and
kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleti
Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form pag
phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application dire
phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes
The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attri
SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php c
PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30,
WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar
WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar
The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'que
PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically,
PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based bli
Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attack
Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attack
OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries
The List category posts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘starting_with’ parameter
Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated ad
MyNET up to v26.08.316 was discovered to contain an Unauthenticated SQL Injection vulnerability via the intmenu paramete
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker
SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editi
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file
Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters ar
A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part
A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. This vulnerability affects unknow
A vulnerability, which was classified as critical, has been found in code-projects Job Recruitment 1.0. This issue affec
A vulnerability, which was classified as critical, was found in code-projects Chat System 1.0. Affected is an unknown fu
A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. Affected by this vulnerabili
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as critical. Affected by this issue i
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been classified as
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as crit
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as crit
A vulnerability classified as critical has been found in code-projects Point of Sales and Inventory Management System 1.
A vulnerability classified as critical was found in code-projects Point of Sales and Inventory Management System 1.0. Th
A vulnerability, which was classified as critical, has been found in code-projects Point of Sales and Inventory Manageme
A vulnerability, which was classified as critical, was found in code-projects Point of Sales and Inventory Management Sy
A vulnerability has been found in code-projects Point of Sales and Inventory Management System 1.0 and classified as cri
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical
A vulnerability was found in code-projects Student Management System 1.0. It has been declared as critical. This vulnera
A vulnerability was found in code-projects Online Shoe Store 1.0. It has been rated as critical. This issue affects some
A vulnerability classified as critical has been found in code-projects Online Shoe Store 1.0. Affected is an unknown fun
A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. This affects an unk
A vulnerability was found in Campcodes Student Grading System 1.0. It has been classified as critical. This affects an u
A vulnerability, which was classified as critical, has been found in code-projects Travel Management System 1.0. This is
A vulnerability, which was classified as critical, was found in code-projects Responsive Hotel Site 1.0. Affected is an
A vulnerability has been found in Codezips Gym Management System 1.0 and classified as critical. Affected by this vulner
A vulnerability was found in Codezips Blood Bank Management System 1.0 and classified as critical. Affected by this issu
A vulnerability was found in code-projects Online Book Shop 1.0. It has been classified as critical. This affects an unk
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started