Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 261/324
7.2
CVE-2022-31058

Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior

7.2
CVE-2022-33057

Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /

7.2
CVE-2022-33058

Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /

7.2
CVE-2022-33059

Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /

7.2
CVE-2022-33060

Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /

7.2
CVE-2022-33061

Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /

7.2
CVE-2021-44915

Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category.

7.2
CVE-2022-32416

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.

7.2
CVE-2022-34042

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /

7.2
CVE-2022-34590

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS

7.2
CVE-2022-35421

Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the pname pa

7.2
CVE-2022-34871

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication

7.2
CVE-2022-31659

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with a

7.2
CVE-2022-25811

The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby pa

7.2
CVE-2022-2593

The Better Search Replace WordPress plugin before 1.4.1 does not properly sanitise and escape table data before insertin

7.2
CVE-2022-1123

The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitiz

7.2
CVE-2022-2559

The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters befo

7.2
CVE-2022-36674

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sche

7.2
CVE-2022-36675

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sche

7.2
CVE-2022-36676

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /cate

7.2
CVE-2022-36754

Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/deb

7.2
CVE-2022-2717

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection v

7.2
CVE-2022-2718

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection v

7.2
CVE-2022-1807

Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall ol

7.2
CVE-2022-38255

Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /interv

7.2
CVE-2022-38260

Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/de

7.2
CVE-2022-38265

Apartment Visitor Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid paramete

7.2
CVE-2022-38267

School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo

7.2
CVE-2022-38268

School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo

7.2
CVE-2022-38269

School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo

7.2
CVE-2022-38272

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list.

7.2
CVE-2022-38273

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.

7.2
CVE-2022-38274

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.

7.2
CVE-2022-38275

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.

7.2
CVE-2022-38276

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.

7.2
CVE-2022-38277

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list.

7.2
CVE-2022-38278

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.

7.2
CVE-2022-38279

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list.

7.2
CVE-2022-38280

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.

7.2
CVE-2022-38281

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list.

7.2
CVE-2022-38282

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list.

7.2
CVE-2022-38283

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list.

7.2
CVE-2022-38284

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list.

7.2
CVE-2022-38285

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list.

7.2
CVE-2022-38286

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list.

7.2
CVE-2022-38605

Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi

7.2
CVE-2022-38606

Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed

7.2
CVE-2022-38610

Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed

7.2
CVE-2022-38302

Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /mai

7.2
CVE-2022-38303

Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /emp

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started