CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authent
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticate
Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the log query module.
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers
TaxonWorks is a web-based workbench designed for taxonomists and biodiversity scientists. Prior to version 0.34.0, a SQL
szvone vmqphp <=1.13 is vulnerable to SQL Injection. Unauthorized remote users can use sql injection attacks to obtain t
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide
There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information
SQL Injection in GitHub repository librenms/librenms prior to 23.10.0.
Nocodb is an open source Airtable alternative. Affected versions of nocodb contain a SQL injection vulnerability, that a
Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.
SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actio
SQL injection vulnerability in addTask.php in Code-Projects Simple Task List 1.0 allows attackers to obtain sensitive in
Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in a
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, the sa
Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special f
A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow fo
Auth. SQL Injection') vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.7.0 versions.
IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-de
SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay
The FareHarbor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessi
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in 82Flex WEIPDCRM. It has been classified as critical. This a
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to SQL injection. A remote attacker c
A vulnerability was found in slackero phpwcms up to 1.9.26 and classified as critical. Affected by this issue is some un
A vulnerability has been found in SourceCodester Loan Management System and classified as critical. This vulnerability a
A vulnerability classified as critical has been found in lojban jbovlaste. This affects an unknown part of the file dict
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could sen
A vulnerability classified as critical has been found in TuziCMS 2.0.6. This affects the function index of the file App\
A vulnerability classified as critical was found in TuziCMS 2.0.6. This vulnerability affects the function delall of the
A vulnerability, which was classified as critical, has been found in SourceCodester Online Flight Booking Management Sys
A vulnerability was found in aeharding classroom-engagement-system and classified as critical. Affected by this issue is
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affecte
A vulnerability was found in SourceCodester Online Flight Booking Management System. It has been rated as critical. Affe
A vulnerability classified as critical has been found in SourceCodester Online Flight Booking Management System. This af
A vulnerability was found in SourceCodester Online Food Ordering System. It has been rated as critical. Affected by this
A vulnerability classified as critical has been found in SourceCodester Online Food Ordering System. This affects an unk
A vulnerability classified as critical was found in SourceCodester Online Food Ordering System. This vulnerability affec
A vulnerability was found in copperwall Twiddit. It has been rated as critical. This issue affects some unknown processi
A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System
A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System
A vulnerability, which was classified as critical, was found in Calendar Event Management System 2.3.0. This affects an
A vulnerability, which was classified as critical, has been found in SourceCodester Medical Certificate Generator App 1.
A vulnerability was found in glorylion JFinalOA 1.0.2 and classified as critical. This issue affects some unknown proces
A vulnerability was found in webbuilders-group silverstripe-kapost-bridge 0.3.3. It has been declared as critical. Affec
A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been declared as critical. This vulner
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulne
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started