CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.
renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component
An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allow
SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code
OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint h
WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exis
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an at
CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify t
A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, up
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module construct
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-8
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a ce
WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exist
An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benk
Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Bool
Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnera
Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.
Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.
SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability
WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exis
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php fi
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog
SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scito
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions
Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection vi
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters
PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL q
EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/template
The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fail
Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_upda
Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute a
PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at l
A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment Syst
A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollme
itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename'
A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System
SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password p
PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteC
Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, al
A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated
In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started