Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 196/324
9.8
CVE-2023-23155

Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the usernam

9.8
CVE-2023-23156

Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par

9.8
CVE-2023-24253

Domotica Labs srl Ikon Server before v2.8.6 was discovered to contain a SQL injection vulnerability.

9.8
CVE-2023-24258

SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerabil

9.8
CVE-2023-1064

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighb

9.8
CVE-2023-23315

The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The

9.8
CVE-2021-3854

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Us

9.8
CVE-2023-26780

CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection.

9.8
CVE-2022-46501

Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the

9.8
CVE-2023-24641

Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms

9.8
CVE-2023-24642

Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms

9.8
CVE-2023-24643

Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms

9.8
CVE-2023-0979

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData MedDataPAC

9.8
CVE-2021-36392

In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.

9.8
CVE-2021-36393

In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

9.8
CVE-2022-3760

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia

9.8
CVE-2023-24781

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member

9.8
CVE-2023-24775

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member

9.8
CVE-2023-24780

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns

9.8
CVE-2023-1267

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company Ptte

9.8
CVE-2023-24773

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list

9.8
CVE-2023-26922

SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the

9.8
CVE-2023-24782

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit

9.8
CVE-2023-24777

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.

9.8
CVE-2023-1251

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. T

9.8
CVE-2023-27202

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/

9.8
CVE-2023-27203

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/

9.8
CVE-2023-27204

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/

9.8
CVE-2023-27205

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxt

9.8
CVE-2023-27207

Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/

9.8
CVE-2023-27210

Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/

9.8
CVE-2023-27213

Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata paramet

9.8
CVE-2023-27214

Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate

9.8
CVE-2023-1091

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Wa

9.8
CVE-2023-24774

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\au

9.8
CVE-2023-1198

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities

9.8
CVE-2023-25207

PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.

9.8
CVE-2023-27052

E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user

9.8
CVE-2023-27074

BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter i

9.8
CVE-2023-24726

Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on t

9.8
CVE-2023-26784

SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code v

9.8
CVE-2023-27250

Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.

9.8
CVE-2023-27041

School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/

9.8
CVE-2023-1152

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information

9.8
CVE-2023-26905

An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue i

9.8
CVE-2023-1153

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows S

9.8
CVE-2023-27569

The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.

9.8
CVE-2023-27570

The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.

9.8
CVE-2023-27637

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req

9.8
CVE-2023-27638

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started