Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 231/324
5.5
CVE-2013-10017

A vulnerability was found in fanzila WebFinance 0.5. It has been classified as critical. Affected is an unknown function

5.5
CVE-2013-10018

A vulnerability was found in fanzila WebFinance 0.5. It has been declared as critical. Affected by this vulnerability is

5.5
CVE-2014-125084

A vulnerability, which was classified as critical, has been found in Gimmie Plugin 1.2.2 on vBulletin. This issue affect

5.5
CVE-2014-125085

A vulnerability, which was classified as critical, was found in Gimmie Plugin 1.2.2 on vBulletin. Affected is an unknown

5.5
CVE-2014-125086

A vulnerability has been found in Gimmie Plugin 1.2.2 on vBulletin and classified as critical. Affected by this vulnerab

5.5
CVE-2023-0707

A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been rated as critical. Affect

5.5
CVE-2011-10002

A vulnerability classified as critical has been found in weblabyrinth 0.3.1. This affects the function Labyrinth of the

5.5
CVE-2011-10003

A vulnerability was found in XpressEngine up to 1.4.4. It has been rated as critical. This issue affects some unknown pr

5.5
CVE-2015-10076

A vulnerability was found in dimtion Shaarlier up to 1.2.2. It has been declared as critical. Affected by this vulnerabi

5.5
CVE-2015-10084

A vulnerability was found in irontec klear-library chloe and classified as critical. Affected by this issue is the funct

5.5
CVE-2023-1057

A vulnerability was found in SourceCodester Doctors Appointment System 1.0. It has been rated as critical. Affected by t

5.5
CVE-2023-1165

A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown pa

5.5
CVE-2023-1736

A vulnerability, which was classified as critical, has been found in SourceCodester Young Entrepreneur E-Negosyo System

5.5
CVE-2023-27610

Auth. (admin+) SQL Injection (SQLi) vulnerability in TransbankDevelopers Transbank Webpay REST plugin <= 1.6.6 versions.

5.5
CVE-2021-4336

A vulnerability was found in ITRS Group monitor-ninja up to 2021.11.1. It has been rated as critical. Affected by this i

5.5
CVE-2023-3100

A vulnerability, which was classified as critical, has been found in IBOS 4.5.5. Affected by this issue is the function

5.5
CVE-2023-3449

A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects the function acti

5.5
CVE-2016-15034

A vulnerability was found in Dynacase Webdesk and classified as critical. Affected by this issue is the function freedom

5.5
CVE-2018-25088

A vulnerability, which was classified as critical, was found in Blue Yonder postgraas_server up to 2.0.0b2. Affected is

5.5
CVE-2023-28019

Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL querie

5.5
CVE-2023-3793

A vulnerability was found in Weaver e-cology. It has been rated as critical. This issue affects some unknown processing

5.5
CVE-2023-3795

A vulnerability classified as critical was found in Bug Finder ChainCity Real Estate Investment Platform 1.0. Affected b

5.5
CVE-2023-3801

A vulnerability was found in IBOS OA 4.5.5. It has been declared as critical. Affected by this vulnerability is the func

5.5
CVE-2023-26443

Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitizati

5.5
CVE-2023-4165

A vulnerability, which was classified as critical, was found in Tongda OA. This affects an unknown part of the file gene

5.5
CVE-2023-4166

A vulnerability has been found in Tongda OA and classified as critical. This vulnerability affects unknown code of the f

5.5
CVE-2023-38905

SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via th

5.5
CVE-2023-4446

A vulnerability, which was classified as critical, was found in OpenRapid RapidCMS 1.3.1. This affects an unknown part o

5.5
CVE-2023-4712

A vulnerability, which was classified as critical, was found in Xintian Smart Table Integrated Management System 5.6.9.

5.5
CVE-2023-4713

A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects the function addC

5.5
CVE-2023-35683

In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injec

5.5
CVE-2023-4987

A vulnerability, which was classified as critical, has been found in infinitietech taskhub 2.8.7. Affected by this issue

5.5
CVE-2023-5017

A vulnerability was found in lmxcms up to 1.41. It has been rated as critical. Affected by this issue is some unknown fu

5.5
CVE-2023-5023

A vulnerability was found in Tongda OA 2017 and classified as critical. Affected by this issue is some unknown functiona

5.5
CVE-2023-5029

A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /cat

5.5
CVE-2023-5030

A vulnerability has been found in Tongda OA up to 11.10 and classified as critical. This vulnerability affects unknown c

5.5
CVE-2023-5261

A vulnerability, which was classified as critical, was found in Tongda OA 2017. Affected is an unknown function of the f

5.5
CVE-2023-5265

A vulnerability, which was classified as critical, has been found in Tongda OA 2017. Affected by this issue is some unkn

5.5
CVE-2023-5267

A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of

5.5
CVE-2023-5269

A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as critical. Affe

5.5
CVE-2023-5270

A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been declared as critical. Affect

5.5
CVE-2023-5271

A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been rated as critical. Affected

5.5
CVE-2023-5272

A vulnerability classified as critical has been found in SourceCodester Best Courier Management System 1.0. This affects

5.5
CVE-2023-5298

A vulnerability was found in Tongda OA 2017. It has been rated as critical. Affected by this issue is some unknown funct

5.5
CVE-2023-5682

A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of

5.5
CVE-2023-5700

A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affec

5.5
CVE-2023-5782

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown funct

5.5
CVE-2023-5784

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by t

5.5
CVE-2023-5785

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This

5.5
CVE-2023-5826

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by t

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started