CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro
In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This
A vulnerability has been found in Tim Campus Confession Wall and classified as critical. Affected by this vulnerability
A vulnerability was found in TicklishHoneyBee nodau. It has been rated as critical. Affected by this issue is some unkno
A vulnerability, which was classified as critical, has been found in m0ver bible-online. Affected by this issue is the f
In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection
In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead t
In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead
A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unkn
A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRo
A vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler
A vulnerability was found in DHBW Fallstudie. It has been declared as critical. Affected by this vulnerability is an unk
A vulnerability was found in challenge website. It has been rated as critical. This issue affects some unknown processin
A vulnerability was found in simple_php_link_shortener. It has been classified as critical. Affected is an unknown funct
A vulnerability was found in KBase Metrics. It has been classified as critical. This affects the function upload_user_da
A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a rem
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service
Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] i
A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and We
An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiA
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_
There is a SQL injection vulnerability in ZTE ZAIP-AIE. Due to lack of input verification by the server, an attacker cou
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is
A vulnerability was found in SourceCodester Canteen Management System. It has been rated as critical. This issue affects
GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of r
SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.
The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter bef
The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using
The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an
Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php.
OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the backgroun
MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\incl
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php.
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php.
AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management fun
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management fun
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Managemen
A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unkn
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affe
A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unk
A vulnerability was found in PHPList 3.2.6. It has been classified as critical. Affected is an unknown function of the f
A vulnerability has been found in Online Hotel Booking System 1.0 and classified as critical. Affected by this vulnerabi
A vulnerability was found in Online Hotel Booking System 1.0 and classified as critical. Affected by this issue is some
A vulnerability classified as critical has been found in SourceCodester Gym Management System. This affects an unknown p
A vulnerability, which was classified as critical, was found in Sports Club Management System 119. This affects an unkno
A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some un
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started