CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated
Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL c
A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote
wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parame
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-3230
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint pas
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Kysely is a type-safe TypeScript SQL query builder. In versions 0.28.12 and 0.28.13, the `sanitizeStringLiteral` method
Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStr
Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's
** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to sanitize category IDs before incorporating them into dyn
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based bli
ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTy
ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL in
Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap
PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for
Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the roo
SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionalit
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query
OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticat
Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements use
FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authe
FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the fil
In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenti
Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-g
A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versi
A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM
A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-fe
The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a S
A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via th
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does n
The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is
The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it i
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an
phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by trunc
Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Info
Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection t
SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that
In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync all
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started