Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 191/324
5.4
CVE-2024-30866

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php.

5.4
CVE-2024-29386

projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceE

5.4
CVE-2024-22856

A SQL injection vulnerability via the Save Favorite Search function in Axefinance Axe Credit Portal >= v.3.0 allows auth

5.4
CVE-2023-24204

SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to exe

5.4
CVE-2024-35085

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMa

5.4
CVE-2024-33803

A SQL injection vulnerability in /model/get_exam.php in campcodes Complete Web-Based School Management System 1.0 allows

5.4
CVE-2024-33807

A SQL injection vulnerability in /model/get_teacher_timetable.php in campcodes Complete Web-Based School Management Syst

5.4
CVE-2024-35548

A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database informatio

5.4
CVE-2024-35468

A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers

5.4
CVE-2024-29168

Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST

5.4
CVE-2024-29169

Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST A

5.4
CVE-2024-37799

CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_i

5.4
CVE-2024-45875

The create user function in baltic-it TOPqw Webportal 1.35.287.1 (fixed in version1.35.291), in /Apps/TOPqw/BenutzerMana

5.4
CVE-2024-11025

An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administrat

5.4
CVE-2024-53364

A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php.

5.3
CVE-2023-48259

The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft

5.3
CVE-2023-48260

The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft

5.3
CVE-2023-48261

The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a craft

5.3
CVE-2024-25896

ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.

5.3
CVE-2024-24407

SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive informa

5.3
CVE-2024-30861

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/configguide/ipsec_guide_1.php.

5.3
CVE-2023-45503

SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denia

5.3
CVE-2024-33161

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedL

5.3
CVE-2024-34930

A SQL injection vulnerability in /model/all_events1.php in Campcodes Complete Web-Based School Management System 1.0 all

5.3
CVE-2024-35357

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif

5.3
CVE-2024-41238

A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an

5.3
CVE-2024-10540

The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL I

5.3
CVE-2024-49773

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input val

5.1
CVE-2024-30872

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.

4.9
CVE-2020-26627

A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker t

4.9
CVE-2020-26630

A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker t

4.9
CVE-2024-25288

SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.

4.9
CVE-2023-49544

A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unaut

4.9
CVE-2024-0956

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is

4.9
CVE-2024-4890

A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' pr

4.9
CVE-2024-41803

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CM

4.9
CVE-2019-25212

The video carousel slider with lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in al

4.9
CVE-2019-25218

The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to SQL Injection via the 'id' par

4.9
CVE-2024-9475

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection

4.9
CVE-2024-9874

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injecti

4.9
CVE-2021-1470

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated

4.9
CVE-2024-52725

SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code v

4.9
CVE-2024-11009

The Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) plugin for WordPress is vulnerable

4.9
CVE-2024-11710

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to

4.9
CVE-2024-11713

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to

4.9
CVE-2024-11714

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to

4.9
CVE-2024-9678

An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arb

4.9
CVE-2024-10862

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to SQL Injection

4.7
CVE-2024-0459

A vulnerability has been found in Blood Bank & Donor Management 5.6 and classified as critical. This vulnerability affec

4.7
CVE-2024-0502

A vulnerability was found in SourceCodester House Rental Management System 1.0 and classified as critical. Affected by t

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started