CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /mai
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent
TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/inde
Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/de
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId p
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&group
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.
Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,
Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id
Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id.
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_leave_t
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_designa
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_applica
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_message.
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_booking.
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/manage_storage.php?id
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=.
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/inquiries/view_details.php?id=
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /lea
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/ad
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/ad
Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=.
Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=.
Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/admin/?page=user/manage_user&id=.
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
SQL injection vulnerability in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via a crafted POST reque
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at
Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/classes/Master.php?f=delete_storage.
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started