CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/?p=products/view_product&id=.
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/vi
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/vi
The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.
Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter.
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /
JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.
SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0
An issue was discovered in 72crm 9.0. There is a SQL Injection vulnerability in View the task calendar.
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/mo
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Textbook parameter at /ad
Kensite CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities via the name and oldname parameters at
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /libraria
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user p
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is ma
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php
SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserF
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /f
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker.
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters
JFinal CMS 5.1.0 is vulnerable to SQL Injection.
ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements
The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By addin
The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL stat
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id9
This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also i
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote at
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started