CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.
SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1.
Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent chang
Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/c
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shop
SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.
Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.
SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attacke
SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.
Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid paramete
The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL state
There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to by
Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.
logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.
A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary S
The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iO
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating
Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request.
A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated
dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query.
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tut
cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL
Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability.
Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.
Database Software Accreditation Tracking/Presentation Module product before version 2 has an unauthenticated SQL Injecti
The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticate
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Pr
Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPre
Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended fil
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch
SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0.
RG-EG series gateway EG350 EG_RGOS 11.1(6) was discovered to contain a SQL injection vulnerability via the function get_
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage
The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcooki
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is
The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using
The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL state
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authentica
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers
A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attack
In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query
pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started