Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 189/324
6.3
CVE-2024-12939

A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the fu

6.3
CVE-2024-12941

A vulnerability was found in CodeAstro Blood Donor Management System 1.0 and classified as critical. This issue affects

6.3
CVE-2024-12947

A vulnerability was found in Codezips Hospital Management System 1.0 and classified as critical. Affected by this issue

6.3
CVE-2024-12948

A vulnerability was found in code-projects Travel Management System 1.0. It has been classified as critical. This affect

6.3
CVE-2024-12949

A vulnerability was found in code-projects Travel Management System 1.0. It has been declared as critical. This vulnerab

6.3
CVE-2024-12950

A vulnerability was found in code-projects/projectworlds Travel Management System 1.0. It has been rated as critical. Th

6.3
CVE-2024-12977

A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 1.0. This affects

6.3
CVE-2024-12981

A vulnerability was found in CodeAstro Car Rental System 1.0. It has been declared as critical. Affected by this vulnera

6.3
CVE-2024-12999

A vulnerability has been found in PHPGurukul Small CRM 1.0 and classified as critical. This vulnerability affects unknow

6.3
CVE-2024-13000

A vulnerability was found in PHPGurukul Small CRM 1.0 and classified as critical. This issue affects some unknown proces

6.3
CVE-2024-13001

A vulnerability was found in PHPGurukul Small CRM 1.0. It has been classified as critical. Affected is an unknown functi

6.3
CVE-2024-13003

A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been rated as critical. Affected

6.3
CVE-2024-13005

A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulner

6.3
CVE-2024-13007

A vulnerability, which was classified as critical, was found in Codezips Event Management System 1.0. Affected is an unk

6.3
CVE-2024-13008

A vulnerability has been found in code-projects Responsive Hotel Site 1.0 and classified as critical. Affected by this v

6.3
CVE-2024-13014

A vulnerability has been found in PHPGurukul Maid Hiring Management System 1.0 and classified as critical. Affected by t

6.3
CVE-2024-13016

A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0. It has been classified as critical. This affe

6.3
CVE-2024-13020

A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an

6.3
CVE-2024-13024

A vulnerability was found in Codezips Blood Bank Management System 1.0 and classified as critical. This issue affects so

6.3
CVE-2024-13025

A vulnerability was found in Codezips College Management System 1.0. It has been classified as critical. Affected is an

6.3
CVE-2024-13035

A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. This vulnerability affects u

6.3
CVE-2024-13036

A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown p

6.3
CVE-2024-13037

A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been classified as critical

6.3
CVE-2024-13039

A vulnerability was found in code-projects Simple Chat System 1.0. It has been rated as critical. Affected by this issue

6.3
CVE-2024-13070

A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been declared as critical. Affected by th

6.3
CVE-2024-13072

A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been rated as critical. Affected

6.3
CVE-2024-13078

A vulnerability has been found in PHPGurukul Land Record System 1.0 and classified as critical. Affected by this vulnera

6.3
CVE-2024-13079

A vulnerability was found in PHPGurukul Land Record System 1.0 and classified as critical. Affected by this issue is som

6.3
CVE-2024-13084

A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is

6.1
CVE-2023-6981

The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerab

6.1
CVE-2024-2387

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for W

6.0
CVE-2021-20451

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially

6.0
CVE-2024-37791

DuxCMS3 v3.1.3 was discovered to contain a SQL injection vulnerability via the keyword parameter at /article/Content/ind

6.0
CVE-2024-40689

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ

6.0
CVE-2024-50801

A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controlle

6.0
CVE-2024-50802

A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controlle

5.9
CVE-2024-0685

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second

5.9
CVE-2024-24256

SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an

5.9
CVE-2024-25848

In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection

5.9
CVE-2024-33407

SQL injection vulnerability in /model/delete_record.php in campcodes Complete Web-Based School Management System 1.0 all

5.9
CVE-2024-25528

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffai

5.9
CVE-2024-34222

Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.

5.9
CVE-2024-35181

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructur

5.9
CVE-2024-35182

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructur

5.9
CVE-2024-36801

A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid par

5.9
CVE-2024-39677

NHibernate is an object-relational mapper for the .NET framework. A SQL injection vulnerability exists in some types imp

5.9
CVE-2024-28145

An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malici

5.9
CVE-2024-11722

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all

5.6
CVE-2024-7651

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to limited SQL Injec

5.5
CVE-2024-0344

A vulnerability, which was classified as critical, has been found in soxft TimeMail up to 1.1. Affected by this issue is

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started