Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 250/324
8.8
CVE-2021-25076

The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in

8.8
CVE-2021-45803

MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is

8.8
CVE-2021-24919

The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it i

8.8
CVE-2022-0366

An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Cap

8.8
CVE-2022-23873

Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary comman

8.8
CVE-2022-0190

The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter o

8.8
CVE-2021-44302

BaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parame

8.8
CVE-2021-25069

The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using

8.8
CVE-2022-24407

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE

8.8
CVE-2021-24704

In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" per

8.8
CVE-2021-24864

The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a S

8.8
CVE-2022-0411

The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a

8.8
CVE-2022-23380

There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit.

8.8
CVE-2021-43077

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.

8.8
CVE-2021-24952

The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data paramet

8.8
CVE-2022-0410

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter

8.8
CVE-2022-0439

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` pa

8.8
CVE-2021-24959

The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJA

8.8
CVE-2022-0478

The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the pos

8.8
CVE-2022-22735

The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX

8.8
CVE-2021-45821

A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file th

8.8
CVE-2021-45791

Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/mem

8.8
CVE-2022-26266

Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.

8.8
CVE-2022-0386

A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code

8.8
CVE-2022-1064

SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1.

8.8
CVE-2022-0983

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability

8.8
CVE-2021-36625

An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the cou

8.8
CVE-2022-23972

ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An u

8.8
CVE-2022-27992

Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class

8.8
CVE-2022-28000

Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id par

8.8
CVE-2022-21210

An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specia

8.8
CVE-2022-21234

An SQL injection vulnerability exists in the EchoAssets.aspx functionality of Lansweeper lansweeper 9.1.20.2. A speciall

8.8
CVE-2022-22149

A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A

8.8
CVE-2022-27908

Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Invent

8.8
CVE-2022-28006

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\empl

8.8
CVE-2022-28007

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cash

8.8
CVE-2022-28008

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\atte

8.8
CVE-2022-28009

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\atte

8.8
CVE-2022-28010

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\over

8.8
CVE-2022-28011

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\sche

8.8
CVE-2022-28012

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\posi

8.8
CVE-2022-28013

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\sche

8.8
CVE-2022-28014

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\atte

8.8
CVE-2022-28015

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cash

8.8
CVE-2022-28016

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\dedu

8.8
CVE-2022-28017

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\over

8.8
CVE-2022-28018

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\sche

8.8
CVE-2022-28019

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\empl

8.8
CVE-2022-28020

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\posi

8.8
CVE-2021-24957

The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a S

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started