Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 131/324
6.3
CVE-2025-11597

A vulnerability was identified in code-projects E-Commerce Website 1.0. The impacted element is an unknown function of t

6.3
CVE-2025-11600

A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected is an unknown func

6.3
CVE-2025-11603

A vulnerability was found in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of t

6.3
CVE-2025-11605

A vulnerability was identified in code-projects Client Details System 1.0. Impacted is an unknown function of the file /

6.3
CVE-2025-11606

A security flaw has been discovered in iPynch Social Network Website up to b6933b6d7f82c84819abe458ccf0e59d61119541. The

6.3
CVE-2025-11610

A security flaw has been discovered in SourceCodester Simple Inventory System 1.0. This issue affects some unknown proce

6.3
CVE-2025-11611

A weakness has been identified in SourceCodester Simple Inventory System 1.0. Impacted is an unknown function of the fil

6.3
CVE-2025-11612

A vulnerability has been found in code-projects Simple Food Ordering System 1.0. This impacts an unknown function of the

6.3
CVE-2025-11613

A vulnerability was found in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file

6.3
CVE-2025-11629

A vulnerability has been found in RainyGao DocSys up to 2.02.36. This impacts the function getUserList of the file /Mana

6.3
CVE-2025-11667

A vulnerability was found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown fun

6.3
CVE-2025-11902

A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findFie

6.3
CVE-2025-11903

A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cm

6.3
CVE-2025-11904

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/mo

6.3
CVE-2025-11909

A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the functi

6.3
CVE-2025-11910

A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the funct

6.3
CVE-2025-11911

A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of t

6.3
CVE-2025-11912

A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file

6.3
CVE-2025-10740

The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provid

6.3
CVE-2025-12238

A security flaw has been discovered in code-projects Automated Voting System 1.0. The affected element is an unknown fun

6.3
CVE-2025-12242

A vulnerability has been found in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown func

6.3
CVE-2025-12243

A vulnerability was found in code-projects Client Details System 1.0. Affected by this issue is some unknown functionali

6.3
CVE-2025-12252

A vulnerability was found in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file

6.3
CVE-2025-12254

A vulnerability was identified in code-projects Online Event Judging System 1.0. Affected by this issue is some unknown

6.3
CVE-2025-12255

A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown part of th

6.3
CVE-2025-12256

A weakness has been identified in code-projects Online Event Judging System 1.0. This vulnerability affects unknown code

6.3
CVE-2025-12261

A vulnerability was found in CodeAstro Gym Management System 1.0. This affects an unknown function of the file /admin/ac

6.3
CVE-2025-12262

A vulnerability was determined in code-projects Online Event Judging System 1.0. This impacts an unknown function of the

6.3
CVE-2025-12263

A vulnerability was identified in code-projects Online Event Judging System 1.0. Affected is an unknown function of the

6.3
CVE-2025-12327

A vulnerability was determined in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. This issue affects s

6.3
CVE-2025-12328

A vulnerability was identified in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. Impacted is an unkno

6.3
CVE-2025-12329

A security flaw has been discovered in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. The affected el

6.3
CVE-2025-12612

A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unkn

6.3
CVE-2025-12926

A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function

6.3
CVE-2025-12930

A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /

6.3
CVE-2025-12931

A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown funct

6.3
CVE-2025-12933

A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatew

6.3
CVE-2025-12939

A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is s

6.3
CVE-2025-13057

A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function o

6.3
CVE-2025-13059

A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown functi

6.3
CVE-2025-13123

A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the f

6.3
CVE-2025-13168

A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the fi

6.3
CVE-2025-13171

A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such

6.3
CVE-2025-13172

A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file

6.3
CVE-2025-13208

A security flaw has been discovered in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. The im

6.3
CVE-2025-13234

A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function o

6.3
CVE-2025-13236

A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the

6.3
CVE-2025-13243

A vulnerability was found in code-projects Student Information System 2.0. Impacted is an unknown function of the file /

6.3
CVE-2025-13251

A flaw has been found in WeiYe-Jing datax-web up to 2.1.2. Affected is an unknown function. Executing manipulation can l

6.3
CVE-2025-13253

A vulnerability was determined in projectworlds Advanced Library Management System 1.0. This affects an unknown part of

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started