CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Contributor SQL Injection in Gallery <= 4.7.8 versions.
Contributor SQL Injection in WP Post Author <= 3.9.1 versions.
Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.
Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.
Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.
Sales Representative SQL Injection in Groundhogg <= 4.5 versions.
SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary C
Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.
Contributor SQL Injection in iNET Webkit 1.2.4 versions.
Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.
Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an S
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vit
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP In
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVG
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExpe
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'All
Contributor SQL Injection in eRoom <= 1.7.1 versions.
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualiz
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neu
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics
Subscriber SQL Injection in Do Lasso <= 358 versions.
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to in
Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper
In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalat
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started