CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to e
DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbit
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in
Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.
Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerabi
Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\
Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora F
SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including acces
The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL s
A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in pr
Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.
In the module "Channable" (channable) up to version 3.2.1 from Channable for PrestaShop, a guest can perform SQL injecti
In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL inje
In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection.
An issue in DataLife Engine v.17.1 and before is vulnerable to SQL Injection in dboption.
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f
The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘conditi
In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injec
SQL injection vulnerability in the module "Complete for Create a Quote in Frontend + Backend Pro" (askforaquotemodul) <=
SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attacker
The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all v
A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data. Likely imp
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive
Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar
Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can injec
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f
SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the sear
EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplat
SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows
SQL injection vulnerability in view_payslip.php in Itsourcecode Payroll Management System Project In PHP With Source Cod
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para
AguardNet's Space Management System does not properly validate user input, allowing unauthenticated remote attackers to
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection
SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0
Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerabilit
ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update
1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of t
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software
The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started