CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability, which was classified as critical, has been found in 07FLY CRM V2. This issue affects some unknown proce
A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected i
A vulnerability was found in SourceCodester Judging Management System 1.0. It has been declared as critical. This vulner
A vulnerability classified as critical was found in Tongda OA 2017 11.10. This vulnerability affects unknown code of the
A vulnerability was found in Shaanxi Chanming Education Technology Score Query System 5.0. It has been rated as critical
A vulnerability was found in PHPGurukul Online Railway Catering System 1.0. It has been classified as critical. Affected
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0 and classified as critical. This issue
A vulnerability was found in Nanning Ontall Longxing Industrial Development Zone Project Construction and Installation M
A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an u
A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknow
A vulnerability, which was classified as critical, has been found in AMTT HiBOS 1.0. Affected by this issue is some unkn
A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. Th
A vulnerability was found in code-projects Matrimonial Site 1.0. It has been classified as critical. Affected is an unkn
A vulnerability was found in code-projects Matrimonial Site 1.0. It has been declared as critical. Affected by this vuln
A vulnerability, which was classified as critical, has been found in Hongjing e-HR 2020. Affected by this issue is some
A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. This affec
A vulnerability has been found in Campcodes Online College Library System 1.0 and classified as critical. This vulnerabi
A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. This affec
A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected
The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it
The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /hss/cla
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
The Conditional Payment Methods for WooCommerce WordPress plugin through 1.0 does not properly sanitise and escape a par
All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL
ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the EID parameter at GetText.php.
ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Eve
The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL sta
SQL Injection vulnerability in Ehoney version 2.0.0 in models/protocol.go and models/images.go, allows attackers to exec
An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability
The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the ‘
The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it i
An issue was discovered in Online Reviewer Management System v1.0. There is a SQL injection that can directly issue inst
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_*
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_*
HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated rem
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter a
DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php.
The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user i
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The Info
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/index.php?page=edit_faculty&id=.
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started