CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php/ajax.php.
A vulnerability classified as critical has been found in Telecommunication Software SAMwin Contact Center Suite 5.1. Thi
Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection atta
Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /repo
PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the adm
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server m
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remot
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Auth
This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It!
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parame
CandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via th
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update functi
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion func
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerr
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywh
An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the fil
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via Tic
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape
SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the
A vulnerability classified as critical was found in Home Clean Services Management System 1.0. This vulnerability affect
A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22. This vulnerability
A vulnerability classified as critical has been found in MINMAX. This affects an unknown part of the file /newsDia.php.
A vulnerability was found in Brandbugle. It has been rated as critical. Affected by this issue is some unknown functiona
A vulnerability was found in Everywhere CMS. It has been classified as critical. Affected is an unknown function. The ma
A vulnerability was found in Eatan CMS. It has been declared as critical. Affected by this vulnerability is an unknown f
A vulnerability was found in Lógico y Creativo 1.0 and classified as critical. This issue affects some unknown processin
A vulnerability, which was classified as critical, was found in Neetai Tech. Affected is an unknown function of the file
A vulnerability, which was classified as critical, was found in SialWeb CMS. This affects an unknown part of the file /a
A vulnerability, which was classified as critical, has been found in The Next Generation of Genealogy Sitebuilding up to
A vulnerability was found in PHPList 3.2.6. It has been rated as critical. Affected by this issue is some unknown functi
A vulnerability has been found in Navetti PricePoint 4.6.0.0 and classified as critical. Affected by this vulnerability
A vulnerability, which was classified as critical, has been found in SourceCodester Bank Management System 1.0. Affected
A vulnerability was found in SourceCodester Library Management System 1.0. It has been rated as critical. Affected by th
A vulnerability classified as critical has been found in Kama Click Counter Plugin up to 3.4.8. This affects an unknown
A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unkn
A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability
A vulnerability was found in LogoStore. It has been classified as critical. Affected is an unknown function of the file
A vulnerability was found in Itech Real Estate Script 3.12. It has been declared as critical. Affected by this vulnerabi
A vulnerability was found in Itech News Portal 6.28. It has been classified as critical. Affected is an unknown function
A vulnerability was found in Itech Multi Vendor Script 6.49 and classified as critical. This issue affects some unknown
A vulnerability, which was classified as critical, has been found in Itech Freelancer Script 5.13. Affected by this issu
A vulnerability classified as critical was found in Itech Dating Script 3.26. Affected by this vulnerability is an unkno
A vulnerability classified as critical has been found in Itech Classifieds Script 7.27. Affected is an unknown function
A vulnerability was found in Itech B2B Script 4.28. It has been rated as critical. This issue affects some unknown proce
A vulnerability was found in Itech Auction Script 6.49. It has been classified as critical. This affects an unknown part
A vulnerability was found in SourceCodester Garage Management System 1.0 and classified as critical. This issue affects
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started