CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability has been found in DedeBIZ 6.3.0 and classified as critical. This vulnerability affects unknown code of t
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical.
A vulnerability, which was classified as critical, was found in Byzoro Smart S20 Management Platform up to 20231120. Thi
A vulnerability was found in code-projects E-Commerce Website 1.0. It has been classified as critical. Affected is an un
A vulnerability, which was classified as critical, has been found in SourceCodester Web-Based Student Clearance System 1
A vulnerability classified as critical has been found in SourceCodester Petrol Pump Management Software 1.0. This affect
A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. This vulnerabili
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0.
A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affec
A vulnerability, which was classified as critical, has been found in SourceCodester Online Mobile Management Store 1.0.
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as crit
A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authe
A vulnerability has been found in heyewei JFinalCMS 5.0.0 and classified as critical. Affected by this vulnerability is
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. Affected by
A vulnerability, which was classified as critical, has been found in SourceCodester Kortex Lite Advocate Office Manageme
A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management Sy
A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as cri
A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical
A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been classified as
The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin user
phpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/i
A vulnerability classified as critical has been found in lahirudanushka School Management System 1.0.0/1.0.1. This affec
A vulnerability classified as critical was found in lahirudanushka School Management System 1.0.0/1.0.1. This vulnerabil
A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1
A vulnerability, which was classified as critical, was found in lahirudanushka School Management System 1.0.0/1.0.1. Aff
A vulnerability has been found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affect
A vulnerability, which was classified as critical, has been found in itsourcecode Alton Management System 1.0. This issu
A vulnerability, which was classified as critical, was found in itsourcecode Alton Management System 1.0. Affected is an
A vulnerability has been found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this
A vulnerability was found in itsourcecode Alton Management System 1.0. It has been classified as critical. This affects
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL
A vulnerability, which was classified as critical, has been found in itsourcecode Ticket Reservation System 1.0. Affecte
A vulnerability, which was classified as critical, was found in itsourcecode Ticket Reservation System 1.0. This affects
A vulnerability was found in ContiNew Admin 3.2.0 and classified as critical. Affected by this issue is the function top
A vulnerability classified as critical was found in ContiNew Admin 3.2.0. Affected by this vulnerability is the function
A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue aff
The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL s
A vulnerability has been found in LyLme_spage 1.9.5 and classified as critical. This vulnerability affects unknown code
A vulnerability was found in LyLme_spage 1.9.5 and classified as critical. This issue affects some unknown processing of
A vulnerability was found in LyLme_spage 1.9.5. It has been classified as critical. Affected is an unknown function of t
A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as critical. This vulnerability a
A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function
A vulnerability, which was classified as critical, was found in code-projects Blood Bank System up to 1.0. Affected is a
A vulnerability was found in Tecno 4G Portable WiFi TR118 V008-20220830. It has been declared as critical. Affected by t
A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been declared as critical. Affected b
A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been rated as critical. Affected by t
A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an
A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability af
A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started