Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 164/324
7.5
CVE-2024-11711

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to

7.5
CVE-2024-31892

IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized act

7.5
CVE-2024-12025

The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-js

7.5
CVE-2024-11912

The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id

7.5
CVE-2024-54790

A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remo

7.5
CVE-2024-12428

The WP Data Access – App, Table, Form and Chart Builder plugin plugin for WordPress is vulnerable to SQL Injection via t

7.4
CVE-2024-4215

pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker

7.4
CVE-2024-21514

This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido p

7.3
CVE-2024-0182

A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this iss

7.3
CVE-2024-0247

A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affect

7.3
CVE-2024-0267

A vulnerability classified as critical was found in Kashipara Hospital Management System up to 1.0. Affected by this vul

7.3
CVE-2024-0268

A vulnerability, which was classified as critical, has been found in Kashipara Hospital Management System up to 1.0. Aff

7.3
CVE-2024-0306

A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been classified as critical. This

7.3
CVE-2024-0307

A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been declared as critical. This v

7.3
CVE-2024-0359

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical.

7.3
CVE-2024-0474

A vulnerability classified as critical was found in code-projects Dormitory Management System 1.0. Affected by this vuln

7.3
CVE-2024-0479

A vulnerability was found in Taokeyun up to 1.0.5. It has been classified as critical. Affected is the function login of

7.3
CVE-2024-0480

A vulnerability was found in Taokeyun up to 1.0.5. It has been declared as critical. Affected by this vulnerability is t

7.3
CVE-2024-1009

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t

7.3
CVE-2024-1197

A vulnerability, which was classified as critical, has been found in SourceCodester Testimonial Page Manager 1.0. This i

7.3
CVE-2024-1820

A vulnerability was found in code-projects Crime Reporting System 1.0. It has been declared as critical. This vulnerabil

7.3
CVE-2024-1824

A vulnerability, which was classified as critical, has been found in CodeAstro House Rental Management System 1.0. Affec

7.3
CVE-2024-1826

A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affect

7.3
CVE-2024-1827

A vulnerability was found in code-projects Library System 1.0 and classified as critical. This issue affects some unknow

7.3
CVE-2024-1828

A vulnerability was found in code-projects Library System 1.0. It has been classified as critical. Affected is an unknow

7.3
CVE-2024-1829

A vulnerability was found in code-projects Library System 1.0. It has been declared as critical. Affected by this vulner

7.3
CVE-2024-1830

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is

7.3
CVE-2024-1831

A vulnerability, which was classified as critical, was found in SourceCodester Complete File Management System 1.0. Affe

7.3
CVE-2024-1832

A vulnerability has been found in SourceCodester Complete File Management System 1.0 and classified as critical. Affecte

7.3
CVE-2024-1833

A vulnerability was found in SourceCodester Employee Management System 1.0 and classified as critical. Affected by this

7.3
CVE-2024-1876

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected

7.3
CVE-2023-7107

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. Affected by this issue

7.3
CVE-2023-7109

A vulnerability classified as critical was found in code-projects Library Management System 2.0. This vulnerability affe

7.3
CVE-2023-7110

A vulnerability, which was classified as critical, has been found in code-projects Library Management System 2.0. This i

7.3
CVE-2024-1971

A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by thi

7.3
CVE-2024-2147

A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been rated as critical. Affected

7.3
CVE-2023-49968

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_sup

7.3
CVE-2024-2264

A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affecte

7.3
CVE-2024-2282

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue af

7.3
CVE-2024-2514

A vulnerability classified as critical was found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. Affecte

7.3
CVE-2024-2566

A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240313. It has been decl

7.3
CVE-2024-2647

A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gateway 6.3.

7.3
CVE-2024-2014

A vulnerability classified as critical was found in Panabit Panalog 202103080942. This vulnerability affects unknown cod

7.3
CVE-2024-2916

A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected

7.3
CVE-2024-2927

A vulnerability was found in code-projects Mobile Shop 1.0. It has been classified as critical. Affected is an unknown f

7.3
CVE-2024-3000

A vulnerability classified as critical was found in code-projects Online Book System 1.0. This vulnerability affects unk

7.3
CVE-2024-3085

A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is a

7.3
CVE-2024-3087

A vulnerability, which was classified as critical, has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. A

7.3
CVE-2024-3088

A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. This a

7.3
CVE-2024-3226

A vulnerability was found in Campcodes Online Patient Record Management System 1.0. It has been classified as critical.

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started