CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability, which was classified as critical, was found in PHPGurukul Medical Card Generation System 1.0. Affected
A vulnerability classified as critical has been found in SourceCodeHero Clothes Recommendation System 1.0. Affected is a
A vulnerability classified as critical was found in SourceCodeHero Clothes Recommendation System 1.0. Affected by this v
A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulner
A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0.
WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the paren
A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Libra
A vulnerability classified as critical was found in Guangzhou Tuchuang Computer Software Development Interlib Library Cl
A vulnerability was found in CodeAstro Real Estate Management System up to 1.0. It has been declared as critical. This v
A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Aff
A vulnerability has been found in TimGeyssens UIOMatic 5 and classified as critical. This vulnerability affects unknown
A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This
A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functiona
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data store
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZkTeco-based OEM
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talya Informatics
Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially ex
The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL stat
Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A loca
An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_i
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow use
A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_sup
SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to ob
A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. A
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions
An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL
Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to
SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted input
dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to
Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL in
The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it
A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown funct
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute ar
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute ar
An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software v
SQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to ru
Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.
HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability
A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authentic
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected
Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in a
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at h
SQL-Injection in Harbor allows priviledge users to leak the task IDs
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Genians Genian NAC
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Grup Arge Energy a
SQL Injection vulnerability in MegaBIP software allows attacker to disclose the contents of the database, obtain session
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started