Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 137/324
4.7
CVE-2025-11668

A vulnerability was determined in code-projects Automated Voting System 1.0. Affected by this issue is some unknown func

4.7
CVE-2025-11944

A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/control

4.7
CVE-2025-12226

A vulnerability was found in SourceCodester Best House Rental Management System 1.0. Impacted is the function save_house

4.7
CVE-2025-12287

A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 2

4.7
CVE-2025-12294

A security flaw has been discovered in SourceCodester Point of Sales 1.0. Impacted is an unknown function of the file /d

4.7
CVE-2025-12314

A vulnerability was found in code-projects Food Ordering System 1.0. The impacted element is an unknown function of the

4.7
CVE-2025-12315

A vulnerability was determined in code-projects Food Ordering System 1.0. This affects an unknown function of the file /

4.7
CVE-2025-12594

A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown

4.7
CVE-2025-12597

A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability i

4.7
CVE-2025-12598

A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function

4.7
CVE-2025-12609

A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality o

4.7
CVE-2025-12610

A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/v

4.7
CVE-2025-12614

A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delet

4.7
CVE-2025-12853

A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function dele

4.7
CVE-2025-12855

A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processi

4.7
CVE-2025-12856

A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /

4.7
CVE-2025-12857

A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknow

4.7
CVE-2025-12859

A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_

4.7
CVE-2025-12860

A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php.

4.7
CVE-2025-12861

A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the

4.7
CVE-2025-12873

A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /a

4.7
CVE-2025-12913

A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomde

4.7
CVE-2025-12914

A vulnerability has been found in aaPanel BaoTa up to 11.2.x. This vulnerability affects unknown code of the file /datab

4.7
CVE-2025-12927

A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the fi

4.7
CVE-2025-12932

A vulnerability was determined in SourceCodester Baby Care System 1.0. Affected by this issue is some unknown functional

4.7
CVE-2025-13075

A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /ad

4.7
CVE-2025-13076

A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the fil

4.7
CVE-2025-13210

A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. This impacts an unknown func

4.7
CVE-2025-13302

A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file

4.7
CVE-2025-13424

A vulnerability has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file

4.7
CVE-2025-13545

A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3.

4.7
CVE-2025-13586

A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file

4.7
CVE-2025-14011

A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Co

4.7
CVE-2025-14012

A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of

4.7
CVE-2025-14090

A security flaw has been discovered in AMTT Hotel Broadband Operation System 1.0. This affects an unknown part of the fi

4.7
CVE-2025-14694

A vulnerability was found in ketr JEPaaS up to 7.2.8. This impacts the function readAllPostil of the file /je/postil/pos

4.7
CVE-2025-14897

A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown functi

4.7
CVE-2025-14898

A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of

4.7
CVE-2025-14899

A weakness has been identified in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the f

4.7
CVE-2025-14900

A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. Affected is an unknown functi

4.7
CVE-2025-14939

A vulnerability was found in code-projects Online Appointment Booking System 1.0. Impacted is an unknown function of the

4.7
CVE-2025-14966

A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file applic

4.7
CVE-2025-15003

A vulnerability was found in SeaCMS up to 13.3. The impacted element is an unknown function of the file admin_video.php.

4.7
CVE-2025-15143

A security flaw has been discovered in EyouCMS up to 1.7.6. The affected element is an unknown function of the file /app

4.7
CVE-2025-15169

A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected by this issue is some unknown functionality of

4.7
CVE-2023-7331

A vulnerability was detected in PKrystian Full-Stack-Bank up to bf73a0179e3ff07c0d7dc35297cea0be0e5b1317. This vulnerabi

4.4
CVE-2024-51102

PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili

4.3
CVE-2025-22214

Landray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection.

4.3
CVE-2024-35278

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions

4.3
CVE-2025-1726

There is a SQL injection issue in Esri ArcGIS Monitor versions 2023.0 through 2024.x on Windows and Linux that allows a

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started