CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph
An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.p
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page
OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php.
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.
Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploa
A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account.
RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can in
Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=
The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacke
The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to ga
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id pa
Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters befor
MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.
MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.
MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.
CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is pos
The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL I
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL I
WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 befor
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/i
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username pa
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the appli
Dreamer CMS 4.0.01 is vulnerable to SQL Injection.
webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/
College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or pe
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOr
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrde
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOr
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.ph
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started