CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 t
A SQL Injection issue in the request body processing in BOS IPCs with firmware 21.45.8.2.2_220219 before 21.45.8.2.3_230
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (E
HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential
An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to
SQL Injection vulnerability in function getselectdataAjax in file inputAction.php in Xinhu Rainrock RockOA 2.7.0 allowin
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/l
Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Forti
A vulnerability was found in TMD Custom Header Menu 4.0.0.1 on OpenCart. It has been rated as problematic. This issue af
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiS
The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter
The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter
The Gutentor WordPress plugin before 3.4.7 does not sanitize and escape a parameter before using it in a SQL statement,
The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a S
The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statu
The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, a
In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untruste
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file
A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execu
In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This
A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attacke
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3
A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticate
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiW
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiM
An error-based SQL injection vulnerability exists in the Sunbird Power IQ 9.2.0 API. The vulnerability is due to an outd
The Dell Secure Connect Gateway (SCG) Application and Appliance, versions prior to 5.28, contains a SQL injection vulner
Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.
Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abuse
Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-bas
Login functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-base
Document history functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a
Saved search functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time
SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability a
SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker t
Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, w
Clinic’s Patient Management System versions 2.0 suffers from a SQL injection vulnerability in the login page.
The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries. Improper
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (S
Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started