CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is
The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it i
An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Cap
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary comman
The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter o
BaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parame
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE
In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" per
The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a S
The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a
There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit.
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.
The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data paramet
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` pa
The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJA
The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the pos
The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX
A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file th
Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/mem
Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code
SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1.
An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the cou
ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An u
Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class
Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id par
An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specia
An SQL injection vulnerability exists in the EchoAssets.aspx functionality of Lansweeper lansweeper 9.1.20.2. A speciall
A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A
Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Invent
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\empl
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cash
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\atte
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\atte
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\over
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\sche
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\posi
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\sche
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\atte
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cash
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\dedu
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\over
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\sche
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\empl
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\posi
The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a S
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started