Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 14/324
8.8
CVE-2026-78315

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

8.8
CVE-2026-78316

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

8.8
CVE-2026-78317

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

8.8
CVE-2026-19949

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functiona

8.7
CVE-2026-35228

Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The

8.7
CVE-2026-44739

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigActi

8.7
CVE-2026-73332

CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privile

8.6
CVE-2025-27378

AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic f

8.6
CVE-2025-57793

Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user

8.6
CVE-2025-4686

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer

8.6
CVE-2025-69662

SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_po

8.6
CVE-2025-8587

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Tech

8.6
CVE-2025-13379

IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ

8.6
CVE-2025-7631

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tumeva Internet Te

8.6
CVE-2026-3830

The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before

8.6
CVE-2026-30995

Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_v

8.6
CVE-2026-4935

The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before

8.6
CVE-2026-6379

The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before usin

8.6
CVE-2025-30028

A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.

8.6
CVE-2026-3326

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL state

8.6
CVE-2026-12512

The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before us

8.6
CVE-2026-11349

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0

8.6
CVE-2026-48448

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL

8.6
CVE-2026-13395

The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a

8.6
CVE-2026-22620

Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unau

8.6
CVE-2026-12721

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before us

8.6
CVE-2026-16572

The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a

8.6
CVE-2026-3430

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL s

8.6
CVE-2026-17044

The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it

8.6
CVE-2026-19049

The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries,

8.6
CVE-2026-18474

The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta

8.6
CVE-2026-15205

The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before

8.6
CVE-2026-12983

The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowi

8.6
CVE-2026-16950

The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it i

8.6
CVE-2026-16061

The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its

8.5
CVE-2025-31044

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Premium SE

8.5
CVE-2025-69351

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ni

8.5
CVE-2025-22713

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vanquish WooCommer

8.5
CVE-2025-22728

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workrea

8.5
CVE-2025-67921

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VanKarWai Lobo lob

8.5
CVE-2025-49049

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZoomIt DZS Video G

8.5
CVE-2025-49050

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Le

8.5
CVE-2025-68881

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal AppExpe

8.5
CVE-2025-68999

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HappyMonster Happy

8.5
CVE-2025-69045

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FooEvents FooEvent

8.5
CVE-2025-69180

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themepassion Ultra

8.5
CVE-2026-24367

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele

8.5
CVE-2026-24572

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nel

8.5
CVE-2026-25022

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design Kivi

8.5
CVE-2025-67987

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech System

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started