CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the fu
A vulnerability was found in CodeAstro Blood Donor Management System 1.0 and classified as critical. This issue affects
A vulnerability was found in Codezips Hospital Management System 1.0 and classified as critical. Affected by this issue
A vulnerability was found in code-projects Travel Management System 1.0. It has been classified as critical. This affect
A vulnerability was found in code-projects Travel Management System 1.0. It has been declared as critical. This vulnerab
A vulnerability was found in code-projects/projectworlds Travel Management System 1.0. It has been rated as critical. Th
A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 1.0. This affects
A vulnerability was found in CodeAstro Car Rental System 1.0. It has been declared as critical. Affected by this vulnera
A vulnerability has been found in PHPGurukul Small CRM 1.0 and classified as critical. This vulnerability affects unknow
A vulnerability was found in PHPGurukul Small CRM 1.0 and classified as critical. This issue affects some unknown proces
A vulnerability was found in PHPGurukul Small CRM 1.0. It has been classified as critical. Affected is an unknown functi
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been rated as critical. Affected
A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulner
A vulnerability, which was classified as critical, was found in Codezips Event Management System 1.0. Affected is an unk
A vulnerability has been found in code-projects Responsive Hotel Site 1.0 and classified as critical. Affected by this v
A vulnerability has been found in PHPGurukul Maid Hiring Management System 1.0 and classified as critical. Affected by t
A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0. It has been classified as critical. This affe
A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an
A vulnerability was found in Codezips Blood Bank Management System 1.0 and classified as critical. This issue affects so
A vulnerability was found in Codezips College Management System 1.0. It has been classified as critical. Affected is an
A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. This vulnerability affects u
A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown p
A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been classified as critical
A vulnerability was found in code-projects Simple Chat System 1.0. It has been rated as critical. Affected by this issue
A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been declared as critical. Affected by th
A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been rated as critical. Affected
A vulnerability has been found in PHPGurukul Land Record System 1.0 and classified as critical. Affected by this vulnera
A vulnerability was found in PHPGurukul Land Record System 1.0 and classified as critical. Affected by this issue is som
A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is
The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerab
The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for W
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially
DuxCMS3 v3.1.3 was discovered to contain a SQL injection vulnerability via the keyword parameter at /article/Content/ind
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ
A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controlle
A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controlle
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second
SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an
In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection
SQL injection vulnerability in /model/delete_record.php in campcodes Complete Web-Based School Management System 1.0 all
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffai
Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.
Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructur
Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructur
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid par
NHibernate is an object-relational mapper for the .NET framework. A SQL injection vulnerability exists in some types imp
An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malici
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to limited SQL Injec
A vulnerability, which was classified as critical, has been found in soxft TimeMail up to 1.1. Affected by this issue is
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started