Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 117/324
6.5
CVE-2024-44664

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and

6.5
CVE-2025-63512

kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleti

6.5
CVE-2025-63878

Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form pag

6.5
CVE-2025-60797

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application dire

6.5
CVE-2025-60798

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes

6.5
CVE-2025-10144

The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attri

6.5
CVE-2025-61167

SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php c

6.5
CVE-2025-66260

PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30,

6.5
CVE-2025-13769

WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar

6.5
CVE-2025-13770

WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar

6.5
CVE-2025-12483

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'que

6.5
CVE-2025-65379

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically,

6.5
CVE-2025-65380

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username

6.5
CVE-2025-13359

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL

6.5
CVE-2025-13922

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based bli

6.5
CVE-2025-14254

Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attack

6.5
CVE-2025-14255

Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attack

6.5
CVE-2021-47704

OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries

6.5
CVE-2025-10163

The List category posts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘starting_with’ parameter

6.5
CVE-2023-53917

Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated ad

6.5
CVE-2024-39037

MyNET up to v26.08.316 was discovered to contain an Unauthenticated SQL Injection vulnerability via the intmenu paramete

6.5
CVE-2025-68914

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker

6.5
CVE-2025-66947

SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editi

6.4
CVE-2025-25875

A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file

6.4
CVE-2024-43018

Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters ar

6.3
CVE-2025-0168

A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part

6.3
CVE-2024-13092

A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. This vulnerability affects unknow

6.3
CVE-2024-13093

A vulnerability, which was classified as critical, has been found in code-projects Job Recruitment 1.0. This issue affec

6.3
CVE-2025-0171

A vulnerability, which was classified as critical, was found in code-projects Chat System 1.0. Affected is an unknown fu

6.3
CVE-2025-0172

A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. Affected by this vulnerabili

6.3
CVE-2025-0173

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as critical. Affected by this issue i

6.3
CVE-2025-0174

A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been classified as

6.3
CVE-2025-0176

A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as crit

6.3
CVE-2025-0195

A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as crit

6.3
CVE-2025-0196

A vulnerability classified as critical has been found in code-projects Point of Sales and Inventory Management System 1.

6.3
CVE-2025-0197

A vulnerability classified as critical was found in code-projects Point of Sales and Inventory Management System 1.0. Th

6.3
CVE-2025-0198

A vulnerability, which was classified as critical, has been found in code-projects Point of Sales and Inventory Manageme

6.3
CVE-2025-0199

A vulnerability, which was classified as critical, was found in code-projects Point of Sales and Inventory Management Sy

6.3
CVE-2025-0200

A vulnerability has been found in code-projects Point of Sales and Inventory Management System 1.0 and classified as cri

6.3
CVE-2025-0201

A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical

6.3
CVE-2025-0203

A vulnerability was found in code-projects Student Management System 1.0. It has been declared as critical. This vulnera

6.3
CVE-2025-0204

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been rated as critical. This issue affects some

6.3
CVE-2025-0205

A vulnerability classified as critical has been found in code-projects Online Shoe Store 1.0. Affected is an unknown fun

6.3
CVE-2025-0208

A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. This affects an unk

6.3
CVE-2025-0212

A vulnerability was found in Campcodes Student Grading System 1.0. It has been classified as critical. This affects an u

6.3
CVE-2025-0229

A vulnerability, which was classified as critical, has been found in code-projects Travel Management System 1.0. This is

6.3
CVE-2025-0230

A vulnerability, which was classified as critical, was found in code-projects Responsive Hotel Site 1.0. Affected is an

6.3
CVE-2025-0231

A vulnerability has been found in Codezips Gym Management System 1.0 and classified as critical. Affected by this vulner

6.3
CVE-2025-0232

A vulnerability was found in Codezips Blood Bank Management System 1.0 and classified as critical. Affected by this issu

6.3
CVE-2025-0296

A vulnerability was found in code-projects Online Book Shop 1.0. It has been classified as critical. This affects an unk

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started