CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been rated as critical. This is
SAP Busines Objects Business Intelligence Platform (Visual Difference Application) - versions 420, 430, allows an authen
Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=tra
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.
A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authori
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in dns-stats hedgehog. It has been rated as problematic. Affec
In MMSProvider, there is a possible read of protected data due to improper input validationSQL injection. This could lea
The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high
The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in vari
The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in
The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQ
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using t
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy server was disco
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database conten
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote u
Microsoft Defender for IoT Remote Code Execution Vulnerability
Microsoft Defender for IoT Remote Code Execution Vulnerability
TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.a
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the b
A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Ce
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web inter
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through
Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allow
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allow
CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pub
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allo
ISPConfig before 3.2.2 allows SQL injection.
EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the passwo
REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses t
A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauth
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (d
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in thro
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbi
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection
SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variati
Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters,
An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, maliciou
An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail paramet
An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance para
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attacker
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the na
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the na
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started