CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
The WP Popup Banners plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' parameter in versions up to
The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that conca
The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that conc
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.
The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vuln
The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in
The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in
The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s
Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only avail
Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgmen
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication
SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function
The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up t
SQL Injection in the Hardware Inventory report of Security Center 5.11.2.
SQL injection vulnerability found in Tailor Management System v.1 allows a remote authenticated attacker to execute arbi
SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via
SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via
SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via
SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via
SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges v
bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pa
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may
The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via t
Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice
The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQ
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API h
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerabili
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerabili
A SQL injection issue in Logbuch in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allows authenticated atta
SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderS
ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST para
Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and
SQL injection in Log4cxx when using the ODBC appender to send log messages to a database. No fields sent to the databas
SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via
Time Tracker is an open source time tracking system. A time-based blind injection vulnerability existed in Time Tracker
Piwigo before 13.6.0 was discovered to contain a SQL injection vulnerability via the order[0][dir] parameter at user_lis
The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and i
The WP Replicate Post plugin for WordPress is vulnerable to SQL Injection via the post_id parameter in versions up to, a
Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.
hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability.
rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1.
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started