Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 262/324
7.2
CVE-2022-38304

Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /mai

7.2
CVE-2022-38594

Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi

7.2
CVE-2022-38595

Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi

7.2
CVE-2022-38832

School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department

7.2
CVE-2022-38833

School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent

7.2
CVE-2022-35193

TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.

7.2
CVE-2022-38878

School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/inde

7.2
CVE-2022-38576

Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/de

7.2
CVE-2022-40026

SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId p

7.2
CVE-2022-40446

ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&group

7.2
CVE-2022-40447

ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.

7.2
CVE-2022-40933

Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,

7.2
CVE-2022-40934

Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id

7.2
CVE-2022-40935

Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id.

7.2
CVE-2022-40091

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet

7.2
CVE-2022-40092

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet

7.2
CVE-2022-40093

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet

7.2
CVE-2022-40403

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit

7.2
CVE-2022-40926

Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_leave_t

7.2
CVE-2022-40927

Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_designa

7.2
CVE-2022-40928

Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_applica

7.2
CVE-2022-40097

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet

7.2
CVE-2022-40098

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet

7.2
CVE-2022-40099

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet

7.2
CVE-2022-40352

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet

7.2
CVE-2022-40353

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet

7.2
CVE-2022-40354

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet

7.2
CVE-2022-41439

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor

7.2
CVE-2022-41440

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor

7.2
CVE-2022-42241

Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_message.

7.2
CVE-2022-42242

Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_booking.

7.2
CVE-2022-42243

Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/manage_storage.php?id

7.2
CVE-2022-42249

Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=.

7.2
CVE-2022-42250

Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/inquiries/view_details.php?id=

7.2
CVE-2022-41355

Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /lea

7.2
CVE-2022-41513

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-41514

Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

7.2
CVE-2022-41515

Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

7.2
CVE-2022-41377

Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/ad

7.2
CVE-2022-41378

Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/ad

7.2
CVE-2022-42073

Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=.

7.2
CVE-2022-42074

Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=.

7.2
CVE-2022-42230

Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/admin/?page=user/manage_user&id=.

7.2
CVE-2022-41407

Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page

7.2
CVE-2022-41530

Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

7.2
CVE-2022-41532

Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

7.2
CVE-2022-34022

SQL injection vulnerability in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via a crafted POST reque

7.2
CVE-2022-41535

Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

7.2
CVE-2022-41536

Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

7.2
CVE-2022-42232

Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/classes/Master.php?f=delete_storage.

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started