CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the usernam
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par
Domotica Labs srl Ikon Server before v2.8.6 was discovered to contain a SQL injection vulnerability.
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerabil
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighb
The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Us
CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection.
Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData MedDataPAC
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company Ptte
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list
SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. T
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxt
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/
Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata paramet
Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Wa
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\au
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities
PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.
E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user
BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter i
Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on t
SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code v
Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.
School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information
An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows S
The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started