CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.
BlueCMS 1.6 has SQL injection in line 132 of admin/article.php
BlueCMS 1.6 has SQL injection in line 55 of admin/model.php
Bluecms 1.6 has SQL injection in line 132 of admin/area.php
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the sear
A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attac
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ch
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the ok parameter at /admin/hi
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admi
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas
An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob"
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /student/
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/ed
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/bo
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/st
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /lib
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /sta
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /libr
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /libr
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /libraria
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /admin/
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /admi
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /admi
Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?r
Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds
Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can
Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs p
An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanit
In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection.
Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file,
Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the repor
Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/app
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started