CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to send craf
A vulnerability that allows the unauthorized disclosure of authenticated information has been identified in MXsecurity v
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson M
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Dokan – Bes
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter
There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow
Due to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated h
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an
Auth. SQL Injection (SQLi) vulnerability in WP-TopBar <= 5.36 versions.
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product s
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themesgrove Onepag
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking c
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar The Schoo
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kemal YAZICI - Plu
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slidesho
The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-cont
Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php.
SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attack
Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via Calendar
SQL Injection in GitHub repository unilogies/bumsys prior to v2.0.2.
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote att
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/abs
HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when config
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortine
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that
A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow
SQL injection in "/Framewrk/Home.jsp" file (POST method) in tCredence Analytics iDEAL Wealth and Funds - 1.0 iallows aut
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `/dataset/data/{id}` API
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and p
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and p
SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the FundRa
An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to obtain sensitive database c
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started