CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitat
The visitors-online plugin before 0.4 for WordPress has SQL injection.
The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection.
The olimometer plugin before 2.57 for WordPress has SQL injection.
The note-press plugin before 0.1.2 for WordPress has SQL injection.
The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
The duplicate-post plugin before 2.6 for WordPress has SQL injection.
KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?m
The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CV
The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different v
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download En
The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulner
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
The email-newsletter plugin through 20.15 for WordPress has SQL injection.
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.
FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js.
GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input
Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtraction
The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py.
The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.
The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.
OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.
idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.
HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.
BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.
The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.
Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php.
Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php.
Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php.
DianoxDragon Hawn before 2019-07-10 allows SQL injection.
The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.
FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnes
XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key.
XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, a
XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started