CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php.
projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceE
A SQL injection vulnerability via the Save Favorite Search function in Axefinance Axe Credit Portal >= v.3.0 allows auth
SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to exe
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMa
A SQL injection vulnerability in /model/get_exam.php in campcodes Complete Web-Based School Management System 1.0 allows
A SQL injection vulnerability in /model/get_teacher_timetable.php in campcodes Complete Web-Based School Management Syst
A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database informatio
A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers
Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST
Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST A
CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_i
The create user function in baltic-it TOPqw Webportal 1.35.287.1 (fixed in version1.35.291), in /Apps/TOPqw/BenutzerMana
An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administrat
A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php.
The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft
The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft
The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft
ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.
SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive informa
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/configguide/ipsec_guide_1.php.
SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denia
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedL
A SQL injection vulnerability in /model/all_events1.php in Campcodes Complete Web-Based School Management System 1.0 all
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an
The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL I
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input val
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker t
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker t
SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unaut
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is
A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' pr
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CM
The video carousel slider with lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in al
The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to SQL Injection via the 'id' par
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injecti
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code v
The Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) plugin for WordPress is vulnerable
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to
An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arb
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to SQL Injection
A vulnerability has been found in Blood Bank & Donor Management 5.6 and classified as critical. This vulnerability affec
A vulnerability was found in SourceCodester House Rental Management System 1.0 and classified as critical. Affected by t
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started