CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System
A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. This affects
A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerabilit
A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0.
A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. Affec
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. Affected by this vulnera
A vulnerability was found in code-projects Job Recruitment 1.0 and classified as critical. Affected by this issue is the
A vulnerability was found in 1000 Projects Daily College Class Work Report Book 1.0. It has been classified as critical.
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been declared as critical. This v
A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the fu
A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. Affected is the function fln
A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. Affected by this vulnerability is
A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. Affec
A vulnerability, which was classified as critical, has been found in CodeZips Hospital Management System 1.0. Affected b
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. This vulnerability affec
A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected b
A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. This affects an unk
A vulnerability, which was classified as critical, has been found in 1000 Projects Human Resource Management System 1.0.
A vulnerability was found in CodeAstro Simple Loan Management System 1.0. It has been declared as critical. Affected by
A vulnerability, which was classified as critical, has been found in PHPGurukul Land Record System 1.0. Affected by this
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive in
The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using
The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated
The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.
The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using i
Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_categor
Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_retaile
Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distrib
Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&dat
The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticat
Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.
Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'
The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.p
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php
A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attacker
The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' par
SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via
SQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function Dist
Osclass 5.1.2 is vulnerable to SQL Injection.
The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a S
The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin fo
The Action Network plugin for WordPress is vulnerable to SQL Injection via the 'bulk-action' parameter in version 1.4.3
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is
Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e
Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers
Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remot
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote a
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is
The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and includ
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started