CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all vers
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged
Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific p
6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers wit
The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all ve
SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow
SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authe
SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated us
SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenti
SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the
itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.
Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow aut
The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘s
SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially craf
SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obt
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Pane
Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in t
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘k
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker
A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attacker
SQL injection vulnerability in employee-management-system-php-and-mysql-free-download.html taskmatic 1.0 allows a remote
WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to in
The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing
The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regul
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingL
The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and includi
An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated
There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user
A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv func
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated us
MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.
SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to e
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM ve
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient i
A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (ND
A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote atta
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privilege
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged
A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allow
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerabilit
IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ
SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute ar
Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "request" parameter in admin/fe
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS He
SQL injection vulnerability in add_friends.php in campcodes Complete Web-Based School Management System 1.0 allows attac
A SQL injection vulnerability in /view/event1.php in Campcodes Complete Web-Based School Management System 1.0 allows an
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started