CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution Wor
The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress
The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7
The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course soluti
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user
SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote atta
AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive
The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL st
SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device in
Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the
Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the
A SQL injection issue was discovered in ThycoticCentrify Secret Server before 11.0.000007. The only affected versions ar
The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Class
The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vu
iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attack
CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due
An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘mac_fil
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘prod_fi
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filt
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ stat_fi
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cis
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cis
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cis
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cis
In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising cert
SQL injection vulnerabilities in CMFA framework prior to SMR Oct-2021 Release 1 allow untrusted application to overwrite
An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0.
SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcateg
Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via para
Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property int
A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially craf
SQL Injection in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers t
The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allo
Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sit
A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System P
A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authent
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started