CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows r
The login form of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.283.4) at /Apps/TOPqw/Login.aspx is vulne
GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability
GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing it
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via t
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Special Minds Desi
A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP requ
The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based SQL Injection via the ‘tab’ parameter i
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'ser
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sor
The SQL Chart Builder plugin for WordPress is vulnerable to SQL Injection via the 'arg1' arg of the 'gvn_schart_2' short
The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via t
The Responsive Filterable Portfolio plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ve
The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the 'dir_id' parameter in all versions up
The Advanced Floating Content plugin for WordPress is vulnerable to SQL Injection via the 'floating_content_duplicate_po
The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the “wpd
The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL I
The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin f
Veritas / Arctera Data Insight before 7.1.1 allows Application Administrators to conduct SQL injection attacks.
There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all ver
The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_
A vulnerability, which was classified as critical, was found in Kashipara Food Management System up to 1.0. This affects
A vulnerability has been found in Kashipara Food Management System up to 1.0 and classified as critical. This vulnerabil
A vulnerability was found in Kashipara Food Management System up to 1.0 and classified as critical. This issue affects s
A vulnerability was found in Kashipara Food Management System up to 1.0. It has been classified as critical. Affected is
A vulnerability was found in Kashipara Food Management System up to 1.0. It has been declared as critical. Affected by t
A vulnerability was found in Kashipara Food Management System up to 1.0. It has been rated as critical. Affected by this
A vulnerability classified as critical has been found in Kashipara Food Management System up to 1.0. This affects an unk
A vulnerability classified as critical was found in Kashipara Food Management System up to 1.0. This vulnerability affec
A vulnerability, which was classified as critical, has been found in Kashipara Food Management System up to 1.0. This is
A vulnerability, which was classified as critical, was found in Kashipara Food Management System up to 1.0. Affected is
A vulnerability has been found in Kashipara Food Management System up to 1.0 and classified as critical. Affected by thi
A vulnerability was found in Kashipara Food Management System up to 1.0 and classified as critical. Affected by this iss
A vulnerability was found in Kashipara Food Management System 1.0. It has been rated as critical. Affected by this issue
A vulnerability classified as critical has been found in Kashipara Food Management System 1.0. This affects an unknown p
A vulnerability classified as critical was found in Kashipara Food Management System 1.0. This vulnerability affects unk
A vulnerability, which was classified as critical, has been found in Kashipara Food Management System 1.0. This issue af
A vulnerability classified as critical was found in fhs-opensource iparking 1.5.22.RELEASE. This vulnerability affects t
A vulnerability classified as critical has been found in Inis up to 2.0.1. Affected is an unknown function of the file /
A vulnerability, which was classified as critical, was found in SourceCodester Student Attendance System 1.0. Affected i
A vulnerability, which was classified as critical, has been found in ForU CMS up to 2020-06-23. This issue affects some
A vulnerability was found in code-projects Faculty Management System 1.0 and classified as critical. This issue affects
A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been classified as critical. Affected is
A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been declared as critical. Affected by t
A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been rated as critical. Affected by this
A vulnerability classified as critical has been found in code-projects Online Faculty Clearance 1.0. This affects an unk
A vulnerability was found in code-projects Human Resource Integrated System 1.0 and classified as critical. Affected by
A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been classified as critical. Thi
A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been declared as critical. This
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started