Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 16/324
8.5
CVE-2026-57642

Contributor SQL Injection in Gallery <= 4.7.8 versions.

8.5
CVE-2026-57643

Contributor SQL Injection in WP Post Author <= 3.9.1 versions.

8.5
CVE-2026-57644

Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.

8.5
CVE-2026-57653

Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.

8.5
CVE-2026-57662

Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.

8.5
CVE-2026-57663

Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.

8.5
CVE-2026-57667

Sales Representative SQL Injection in Groundhogg <= 4.5 versions.

8.5
CVE-2026-57955

SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary C

8.5
CVE-2025-69094

Subscriber SQL Injection in Unicamp <= 2.2.2 versions.

8.5
CVE-2026-57687

Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.

8.5
CVE-2026-57752

Contributor SQL Injection in iNET Webkit 1.2.4 versions.

8.5
CVE-2026-57756

Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.

8.5
CVE-2026-57765

Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.

8.5
CVE-2026-56690

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an S

8.5
CVE-2026-57385

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vit

8.5
CVE-2026-57771

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD

8.5
CVE-2026-57772

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP In

8.5
CVE-2026-57787

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVG

8.5
CVE-2026-57810

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExpe

8.5
CVE-2026-24552

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'All

8.5
CVE-2026-25405

Contributor SQL Injection in eRoom <= 1.7.1 versions.

8.5
CVE-2026-65450

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

8.5
CVE-2026-65451

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

8.5
CVE-2026-65454

Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

8.5
CVE-2026-65526

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualiz

8.5
CVE-2026-59551

Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

8.5
CVE-2026-65547

Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.

8.5
CVE-2026-65569

Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.

8.5
CVE-2026-17418

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neu

8.5
CVE-2026-28002

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics

8.5
CVE-2026-28156

Subscriber SQL Injection in Do Lasso <= 358 versions.

8.5
CVE-2026-28168

Subscriber SQL Injection in CubeWP <= 1.1.30 versions.

8.5
CVE-2026-66430

Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.

8.5
CVE-2026-66658

Subscriber SQL Injection in Reviewer <= 3.14.2 versions.

8.5
CVE-2026-32466

Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.

8.5
CVE-2026-32552

Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.

8.5
CVE-2026-66668

Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.

8.5
CVE-2026-66594

Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.

8.5
CVE-2026-73998

Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.

8.5
CVE-2026-74013

Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.

8.5
CVE-2026-46682

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to in

8.5
CVE-2026-32471

Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.

8.5
CVE-2026-32478

Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.

8.5
CVE-2026-32550

Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.

8.5
CVE-2026-32564

Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

8.5
CVE-2026-78285

Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.

8.5
CVE-2026-81277

Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.

8.5
CVE-2026-82227

Contributor SQL Injection in WPBulky <= 1.2.2 versions.

8.4
CVE-2025-61943

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper

8.4
CVE-2025-48650

In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalat

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started