CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). Versions pr
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component i
Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vuln
Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Wi
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauth
Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL inje
iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a
JHipster is a development platform to quickly generate, develop, & deploy modern web applications & microservice archite
Elide is a Java library that lets you stand up a GraphQL/JSON-API web service with minimal effort. When leveraging the f
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac
A SQL Injection vulnerability exists in UniverSIS UniverSIS-API through 1.2.1 via the $select parameter to multiple API
imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost.
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and
prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected v
The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attac
Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common N
Ree6 is a moderation bot. This vulnerability allows manipulation of SQL queries. This issue has been patched in version
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is
An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line
Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.
Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vuln
Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vuln
Telephony application has a SQL Injection vulnerability.Successful exploitation of this vulnerability may cause privacy
SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcloud Androi
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post
Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via t
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=c
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via t
SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensi
An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation
SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, all
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m
Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function
SQL injection vulnerability in the phpUploader v1.2 and earlier allows a remote unauthenticated attacker to obtain the i
An issue was discovered in taocms 3.0.2. This is a SQL blind injection that can obtain database data through the Comment
Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a
OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the databas
Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information t
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.
Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.
Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained.
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started