CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A flaw has been found in code-projects Faculty Management System 1.0. The affected element is an unknown function of the
A vulnerability was found in Campcodes Online College Library System 1.0. It has been rated as critical. Affected by thi
A vulnerability classified as critical has been found in Campcodes Online College Library System 1.0. This affects an un
A vulnerability classified as critical was found in Campcodes Online College Library System 1.0. This vulnerability affe
A vulnerability, which was classified as critical, has been found in Campcodes Online College Library System 1.0. This i
A vulnerability, which was classified as critical, was found in Campcodes Online College Library System 1.0. Affected is
A vulnerability classified as critical has been found in karsany OBridge up to 1.3. Affected is the function getAllStand
Cacti is an open source operational monitoring and fault management framework. Issues with Cacti Regular Expression vali
IzyBat Orange casiers before 20221102_1 allows SQL Injection via a getCasier.php?taille= URI.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Fo
A vulnerability was found in jeecg-boot 3.5.0. It has been declared as problematic. Affected by this vulnerability is an
Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.
A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated att
There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SM
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vul
A vulnerability has been found in code-projects Client Details System 1.0 and classified as problematic. This vulnerabil
A vulnerability was found in code-projects Client Details System 1.0 and classified as problematic. This issue affects s
A vulnerability was found in code-projects Client Details System 1.0. It has been classified as problematic. Affected is
A vulnerability was found in code-projects Client Details System 1.0. It has been declared as problematic. Affected by t
An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resultin
Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified i
A vulnerability, which was classified as problematic, has been found in DedeBIZ 6.2.10. Affected by this issue is some u
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted AP
SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise b
A vulnerability classified as problematic has been found in web-cyradm. This affects an unknown part of the file search.
A vulnerability was found in y_project RuoYi up to 4.7.7. It has been classified as problematic. Affected is the functio
FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. Prior
REDCap 12.0.26 LTS and 12.3.2 Standard allows SQL Injection via scheduling, repeatforms, purpose, app_title, or randomiz
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yaztek Software Te
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.p
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacki
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking p
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro
There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version
Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection
Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeho
Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the bac
Arbitrary Code Execution vulnerability in Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.
Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Se
Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.
Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentic
The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise an
cscms v4.1 allows for SQL injection via the "js_del" function.
cscms v4.1 allows for SQL injection via the "page_del" function.
The Le-yan dental management system contains an SQL-injection vulnerability. An unauthenticated remote attacker can inje
dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulne
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started