CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php.
dynamicMarkt <= 3.10 is affected by SQL injection in the kat1 parameter of index.php.
dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php.
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL stateme
The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL sta
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and param
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP fil
The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a mal
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patien
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injec
kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Ho
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in vie
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in a
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/pos
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.ph
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/inde
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=.
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in
Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerabil
IdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO
Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leav
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an
SQL Injection vulnerability in viaviwebtech Android EBook App (Books App, PDF, ePub, Online Book Reading, Download Books
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adm
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doc
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orde
The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions a
Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter
Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_v
Online Accreditation Management v1.0 was discovered to contain a SQL injection vulnerability via the USERNAME parameter
SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via
Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorize
The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter be
The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection.
The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL Injection.
A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.
Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection.
UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileN
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started