Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 170/324
7.3
CVE-2024-12946

A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System

7.3
CVE-2024-12958

A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. This affects

7.3
CVE-2024-12959

A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerabilit

7.3
CVE-2024-12960

A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0.

7.3
CVE-2024-12961

A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. Affec

7.3
CVE-2024-12962

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. Affected by this vulnera

7.3
CVE-2024-12963

A vulnerability was found in code-projects Job Recruitment 1.0 and classified as critical. Affected by this issue is the

7.3
CVE-2024-12964

A vulnerability was found in 1000 Projects Daily College Class Work Report Book 1.0. It has been classified as critical.

7.3
CVE-2024-12965

A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been declared as critical. This v

7.3
CVE-2024-12966

A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the fu

7.3
CVE-2024-12967

A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. Affected is the function fln

7.3
CVE-2024-12968

A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. Affected by this vulnerability is

7.3
CVE-2024-12969

A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. Affec

7.3
CVE-2024-12976

A vulnerability, which was classified as critical, has been found in CodeZips Hospital Management System 1.0. Affected b

7.3
CVE-2024-12978

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. This vulnerability affec

7.3
CVE-2024-13002

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected b

7.3
CVE-2024-13004

A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. This affects an unk

7.3
CVE-2024-13006

A vulnerability, which was classified as critical, has been found in 1000 Projects Human Resource Management System 1.0.

7.3
CVE-2024-13038

A vulnerability was found in CodeAstro Simple Loan Management System 1.0. It has been declared as critical. Affected by

7.3
CVE-2024-13085

A vulnerability, which was classified as critical, has been found in PHPGurukul Land Record System 1.0. Affected by this

7.2
CVE-2023-50162

SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive in

7.2
CVE-2023-6620

The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using

7.2
CVE-2021-24151

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated

7.2
CVE-2022-3764

The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.

7.2
CVE-2023-2655

The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using i

7.2
CVE-2024-22625

Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_categor

7.2
CVE-2024-22626

Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_retaile

7.2
CVE-2024-22627

Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distrib

7.2
CVE-2024-22628

Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&dat

7.2
CVE-2024-0405

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticat

7.2
CVE-2024-24139

Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.

7.2
CVE-2024-24140

Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'

7.2
CVE-2024-0566

The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a

7.2
CVE-2024-25212

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.p

7.2
CVE-2024-25213

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php

7.2
CVE-2023-52155

A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attacker

7.2
CVE-2024-1776

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' par

7.2
CVE-2024-24323

SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via

7.2
CVE-2024-24027

SQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function Dist

7.2
CVE-2024-27515

Osclass 5.1.2 is vulnerable to SQL Injection.

7.2
CVE-2024-1068

The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a S

7.2
CVE-2024-1793

The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin fo

7.2
CVE-2024-2954

The Action Network plugin for WordPress is vulnerable to SQL Injection via the 'bulk-action' parameter in version 1.4.3

7.2
CVE-2024-0913

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is

7.2
CVE-2024-23115

Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e

7.2
CVE-2024-23116

Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers

7.2
CVE-2024-23117

Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remot

7.2
CVE-2024-23118

Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote a

7.2
CVE-2024-0952

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is

7.2
CVE-2024-2344

The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and includ

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started