CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, mu
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, th
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para instituições assistencia
ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the
ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was fou
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was identified in /
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en
ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with th
SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information
AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in pla
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search.
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields.
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDD
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection
WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in da
SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via c
CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTab
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the T
A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbit
### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and
YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerabi
SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_p
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attack
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePd
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as th
BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlle
An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated a
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticate
FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through
The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into Tok
Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabas
Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values dir
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can up
A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) pr
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameter
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started