Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 15/324
8.5
CVE-2026-24959

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help De

8.5
CVE-2026-27373

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome

8.5
CVE-2026-27428

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eagle-Themes Eagle

8.5
CVE-2026-31917

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp

8.5
CVE-2026-31922

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Fox LMS fo

8.5
CVE-2026-32365

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsin

8.5
CVE-2026-32366

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsin

8.5
CVE-2026-32368

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in delphiknight Geo t

8.5
CVE-2026-32399

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi

8.5
CVE-2026-32422

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopme

8.5
CVE-2026-32433

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Cont

8.5
CVE-2026-24977

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Organici

8.5
CVE-2026-25007

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader El

8.5
CVE-2026-27039

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone wooz

8.5
CVE-2026-32516

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Mirac

8.5
CVE-2026-32534

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help De

8.5
CVE-2026-34747

Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs we

8.5
CVE-2026-34885

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi

8.5
CVE-2026-39486

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download

8.5
CVE-2026-39495

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Sc

8.5
CVE-2026-40744

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Bea

8.5
CVE-2026-42741

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms V

8.5
CVE-2026-42742

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPF

8.5
CVE-2026-45211

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExpe

8.5
CVE-2026-45214

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elemento

8.5
CVE-2026-48837

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements

8.5
CVE-2026-44706

Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conver

8.5
CVE-2026-42730

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStu

8.5
CVE-2026-49046

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Dupli

8.5
CVE-2026-49489

OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component

8.5
CVE-2026-24637

Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.

8.5
CVE-2026-40766

Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.

8.5
CVE-2026-48874

Subscriber SQL Injection in GamiPress <= 7.8.7 versions.

8.5
CVE-2026-48882

Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.

8.5
CVE-2026-48964

Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.

8.5
CVE-2026-52697

Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.

8.5
CVE-2026-52700

Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.

8.5
CVE-2026-39581

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

8.5
CVE-2025-69135

Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.

8.5
CVE-2026-22335

Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.

8.5
CVE-2026-48967

Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.

8.5
CVE-2026-49073

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist

8.5
CVE-2026-54185

Subscriber SQL Injection in Cornerstone < 7.8.8 versions.

8.5
CVE-2026-54813

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force S

8.5
CVE-2026-54818

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimsta

8.5
CVE-2026-56012

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi

8.5
CVE-2026-54822

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

8.5
CVE-2026-54838

Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.

8.5
CVE-2026-56064

Subscriber SQL Injection in Tourfic <= 2.22.5 versions.

8.5
CVE-2026-57636

Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started