CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.
A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session toke
Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.
Piccolo is an object-relational mapping and query builder which supports asyncio. Prior to version 1.1.1, the handling o
IzyBat Orange casiers before 20230803_1 allows getEnsemble.php ensemble SQL injection.
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and An
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and An
Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data
The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticate
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote at
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote a
WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstN
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection
SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mang
The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the '
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerabili
The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to p
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication
Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php
A vulnerability in ActiveRecord <6.0.6.1, v6.1.7.1 and v7.0.4.1 related to the sanitization of comments. If malicious us
SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. T
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. T
SQL Injection vulnerability in rttys versions 4.0.0, 4.0.1, 4.0.2, and 4.4.x in api.go, allows attackers to execute arbi
Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible du
The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerabili
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the user
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Desc
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldp
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subj
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authe
jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report c
In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form of affected applicat
PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the conta
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the addre
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the compa
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gende
Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started