CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is req
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Pan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Pan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Pan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Pan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Pan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Pan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Pan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Pan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Pan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Pan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Pan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Pan
Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to
Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated S
The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to in
Telestream Tektronix Medius before 10.7.5 and Sentry before 10.7.5 have a SQL injection vulnerability allowing an unauth
SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_file
SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, get
SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, upd
SQL injection exists in the jdownloads 3.2.63 component for Joomla! via components/com_jdownloads/helpers/categories.php
An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone
The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries
A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issu
cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parame
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could by
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Pag
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementatio
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the news_edit.php news_id parameter is vulnerable to SQL Injectio
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an a
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an a
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remo
SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as
Red Gate SQL Monitor 9.0.13 through 9.2.14 allows an administrative user to perform a SQL injection attack by configurin
fauzantrif eLection 2.0 has SQL Injection via the admin/ajax/op_kandidat.php id parameter.
SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude reques
JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action.
JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Fi
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Har
Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated us
SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by
A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype param
Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commi
Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and acces
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started