CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via t
InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2
An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with app
An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate pr
A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL comm
In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-membe
Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports
SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the d
In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerab
SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Netwo
facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, the $_REQUE
A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter sca
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. T
SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capa
The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a pot
The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using
SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive informatio
SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET r
SQL Injection vulnerability in Reportico Till 8.1.0 allows attackers to obtain sensitive information or other system inf
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter
Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter.
ASUS RT-AX92U lighttpd mod_webdav.so SQL Injection Information Disclosure Vulnerability. This vulnerability allows netwo
phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.
NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with cre
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data store
The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a
A SQL injection vulnerability in /model/get_student_subject.php in campcodes Complete Web-Based School Management System
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress
The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before
KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `report/data/proofofplay
A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privil
Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote at
The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProv
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with ad
A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerl
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al
The League of Legends Shortcodes plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versi
The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' at
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started