Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 248/324
9.8
CVE-2022-40834

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph

9.8
CVE-2022-40835

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.ph

9.8
CVE-2022-40872

An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.p

9.8
CVE-2022-41408

Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page

9.8
CVE-2022-41403

OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at

9.8
CVE-2022-41390

OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php.

9.8
CVE-2022-41391

OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.

9.8
CVE-2022-42064

Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploa

9.8
CVE-2022-42237

A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account.

9.8
CVE-2022-39056

RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can in

9.8
CVE-2022-42021

Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=

9.8
CVE-2022-43774

The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacke

9.8
CVE-2022-43775

The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to ga

9.8
CVE-2022-39976

School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id pa

9.8
CVE-2021-37782

Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.

9.8
CVE-2021-38734

SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.

9.8
CVE-2021-38736

SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.

9.8
CVE-2021-38737

SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.

9.8
CVE-2021-38217

SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.

9.8
CVE-2021-38729

SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.

9.8
CVE-2021-38730

SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.

9.8
CVE-2021-38731

SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.

9.8
CVE-2021-38732

SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.

9.8
CVE-2021-38733

SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.

9.8
CVE-2022-43168

Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.

9.8
CVE-2022-3254

The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters befor

9.8
CVE-2020-22818

MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.

9.8
CVE-2020-22819

MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.

9.8
CVE-2020-22820

MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.

9.8
CVE-2022-42744

CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is pos

9.8
CVE-2022-3481

The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using

9.8
CVE-2022-43058

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

9.8
CVE-2022-43671

Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL I

9.8
CVE-2022-43672

Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL I

9.8
CVE-2022-42984

WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter

9.8
CVE-2022-42120

A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 befor

9.8
CVE-2022-42122

A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through

9.8
CVE-2022-43256

SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/i

9.8
CVE-2022-43262

Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter

9.8
CVE-2022-43135

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username pa

9.8
CVE-2022-44003

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the appli

9.8
CVE-2022-42245

Dreamer CMS 4.0.01 is vulnerable to SQL Injection.

9.8
CVE-2022-36787

webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/

9.8
CVE-2022-39180

College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in

9.8
CVE-2022-4093

SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or pe

9.8
CVE-2022-44785

An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection

9.8
CVE-2022-43214

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOr

9.8
CVE-2022-43215

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrde

9.8
CVE-2022-43212

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOr

9.8
CVE-2022-43213

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.ph

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started