CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/view_faculty.php?id=.
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_subject.php?id=.
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.
SQL Injection in GitHub repository pimcore/customer-data-framework prior to 3.3.10.
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to d
SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0.
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=.
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is authenticated SQL injection
SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the
The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and orde
The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order par
SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the
SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id
The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it
The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL s
A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by
The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versions u
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24.
SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4.
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod
User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injection
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request
Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod
The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and
An SQL Injection vulnerability in the Management Console (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.
SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted scrip
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage hos
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6
Super Store Finder v3.6 and below was discovered to contain a SQL injection vulnerability via the Search parameter at /a
Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection.
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote at
The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using
The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id para
SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary
The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before usin
Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.ph
SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.
Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated
The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started