Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 263/324
7.2
CVE-2022-41416

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet

7.2
CVE-2022-3131

The Search Logger WordPress plugin through 0.9 does not properly sanitise and escape a parameter before using it in a SQ

7.2
CVE-2022-3243

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before u

7.2
CVE-2022-41498

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor

7.2
CVE-2022-42143

Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php.

7.2
CVE-2022-42218

Open Source SACCO Management System v1.0 vulnerable to SQL Injection via /sacco_shield/manage_loan.php.

7.2
CVE-2022-3300

The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it

7.2
CVE-2022-3302

The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using

7.2
CVE-2022-43276

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /p

7.2
CVE-2022-43228

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /

7.2
CVE-2022-43229

Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter

7.2
CVE-2022-43230

Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter

7.2
CVE-2022-43232

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_

7.2
CVE-2022-43233

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_

7.2
CVE-2022-43353

Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /adm

7.2
CVE-2022-43354

Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /adm

7.2
CVE-2022-43355

Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php

7.2
CVE-2022-43124

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43125

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43126

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43127

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43328

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorde

7.2
CVE-2022-43329

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.ph

7.2
CVE-2022-43330

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorde

7.2
CVE-2022-43331

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php_acti

7.2
CVE-2022-43362

Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parame

7.2
CVE-2022-41551

Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed

7.2
CVE-2022-43227

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43066

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43068

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43062

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43063

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43350

Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php

7.2
CVE-2022-43352

Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php

7.2
CVE-2022-42990

Food Ordering Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /foms/all

7.2
CVE-2022-43051

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43052

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43049

Canteen Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the component /youtha

7.2
CVE-2022-43290

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthapp

7.2
CVE-2022-43291

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthapp

7.2
CVE-2022-43292

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthapp

7.2
CVE-2022-43278

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the categoriesId parameter at

7.2
CVE-2022-43279

LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/th

7.2
CVE-2022-44402

Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_transaction.

7.2
CVE-2022-44403

Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=user/manage_user&id=.

7.2
CVE-2022-43162

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43163

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete

7.2
CVE-2022-43179

Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?pa

7.2
CVE-2022-39179

College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed

7.2
CVE-2022-44378

Automotive Shop Management System v1.0 is vulnerable to SQL via /asms/classes/Master.php?f=delete_mechanic.

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started