CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitra
Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_passwo
Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerabilit
The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement vi
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcate
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbran
Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or passwo
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editprod
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoicep
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_
Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php.
A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow fo
This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4
OMICARD EDM’s API function has insufficient validation for user input. An unauthenticated remote attacker can inject arb
The Website File Changes Monitor WordPress plugin before 1.8.3 does not sanitise and escape user input before using it i
Clinic's Patient Management System v1.0 is vulnerable to SQL injection via /pms/update_user.php?id=.
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database u
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName param
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=.
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/Boo
A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to
A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbit
A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbi
A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbi
A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute
Shopro Mall System v1.3.8 was discovered to contain a SQL injection vulnerability via the value parameter.
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /libra
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /studen
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /staf
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staf
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /librar
Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.
Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.
jizhicms v2.3.1 has SQL injection in the background.
Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack
Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started