CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /
Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category.
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS
Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the pname pa
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with a
The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby pa
The Better Search Replace WordPress plugin before 1.4.1 does not properly sanitise and escape table data before insertin
The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitiz
The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters befo
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sche
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sche
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /cate
Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/deb
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection v
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection v
Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall ol
Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /interv
Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/de
Apartment Visitor Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid paramete
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list.
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list.
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /mai
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /emp
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started