Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 217/324
7.2
CVE-2023-31843

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/view_faculty.php?id=.

7.2
CVE-2023-31844

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_subject.php?id=.

7.2
CVE-2023-31845

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.

7.2
CVE-2023-2756

SQL Injection in GitHub repository pimcore/customer-data-framework prior to 3.3.10.

7.2
CVE-2023-31702

SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to d

7.2
CVE-2023-2832

SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0.

7.2
CVE-2023-33439

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=.

7.2
CVE-2022-24628

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is authenticated SQL injection

7.2
CVE-2023-29154

SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the

7.2
CVE-2023-2484

The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and orde

7.2
CVE-2023-2607

The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order par

7.2
CVE-2020-20491

SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the

7.2
CVE-2020-21400

SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id

7.2
CVE-2023-2482

The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it

7.2
CVE-2023-2592

The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL s

7.2
CVE-2023-36968

A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by

7.2
CVE-2023-3023

The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versions u

7.2
CVE-2023-3673

SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24.

7.2
CVE-2023-3820

SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4.

7.2
CVE-2023-31932

Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod

7.2
CVE-2023-31933

Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod

7.2
CVE-2023-31936

Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod

7.2
CVE-2023-31937

Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod

7.2
CVE-2023-21412

User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injection

7.2
CVE-2023-39121

emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.

7.2
CVE-2023-37687

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request

7.2
CVE-2023-3864

Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1

7.2
CVE-2023-31938

SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod

7.2
CVE-2023-31939

SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod

7.2
CVE-2023-31940

SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod

7.2
CVE-2023-31943

SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod

7.2
CVE-2023-31944

SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod

7.2
CVE-2023-31945

SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod

7.2
CVE-2023-2188

The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and

7.2
CVE-2023-21521

An SQL Injection vulnerability in the Management Console  (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could

7.2
CVE-2023-4928

SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.

7.2
CVE-2023-41443

SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted scrip

7.2
CVE-2023-40934

A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage hos

7.2
CVE-2023-40043

In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6

7.2
CVE-2023-44044

Super Store Finder v3.6 and below was discovered to contain a SQL injection vulnerability via the Search parameter at /a

7.2
CVE-2023-44047

Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection.

7.2
CVE-2023-43507

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote at

7.2
CVE-2023-5082

The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using

7.2
CVE-2023-2841

The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id para

7.2
CVE-2023-46956

SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary

7.2
CVE-2023-5108

The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before usin

7.2
CVE-2023-41623

Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.ph

7.1
CVE-2022-38074

SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.

7.1
CVE-2023-36813

Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated

7.1
CVE-2023-26440

The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started