CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet
The Search Logger WordPress plugin through 0.9 does not properly sanitise and escape a parameter before using it in a SQ
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before u
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor
Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php.
Open Source SACCO Management System v1.0 vulnerable to SQL Injection via /sacco_shield/manage_loan.php.
The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it
The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /p
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /
Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter
Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /adm
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /adm
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorde
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.ph
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorde
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php_acti
Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parame
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php
Food Ordering Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /foms/all
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Canteen Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the component /youtha
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthapp
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthapp
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthapp
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the categoriesId parameter at
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/th
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_transaction.
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=user/manage_user&id=.
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?pa
College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed
Automotive Shop Management System v1.0 is vulnerable to SQL via /asms/classes/Master.php?f=delete_mechanic.
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started