Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 300/324
8.8
CVE-2019-12251

sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter.

8.8
CVE-2019-10852

Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.p

8.8
CVE-2016-10754

modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.

8.8
CVE-2016-10755

AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.

8.8
CVE-2019-11970

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than

8.8
CVE-2019-11971

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than

8.8
CVE-2019-11972

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than

8.8
CVE-2019-11973

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than

8.8
CVE-2019-11974

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than

8.8
CVE-2019-11975

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than

8.8
CVE-2019-11976

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than

8.8
CVE-2019-11977

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than

8.8
CVE-2019-11978

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than

8.8
CVE-2019-11979

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than

8.8
CVE-2019-11984

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than

8.8
CVE-2018-16116

SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenti

8.8
CVE-2019-4224

IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send speciall

8.8
CVE-2019-9846

RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreesto

8.8
CVE-2019-12570

A SQL injection vulnerability in the Xpert Solution "Server Status by Hostname/IP" plugin 4.6 for WordPress allows an au

8.8
CVE-2018-13442

SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts T

8.8
CVE-2019-13969

Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_conten

8.8
CVE-2019-13978

Ovidentia 8.4.3 has SQL Injection via the id parameter in an index.php?tg=delegat&idx=mem request.

8.8
CVE-2019-14266

OpenSNS v6.1.0 allows SQL Injection via the index.php?s=/ucenter/Config/ uid parameter because of the getNeedQueryData f

8.8
CVE-2019-14966

An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.

8.8
CVE-2019-15104

An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewT

8.8
CVE-2019-15105

An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in

8.8
CVE-2019-12385

An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to

8.8
CVE-2019-10671

An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queri

8.8
CVE-2017-18597

The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-table

8.8
CVE-2017-18602

The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter.

8.8
CVE-2019-5996

SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execut

8.8
CVE-2016-10949

The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.

8.8
CVE-2016-10950

The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.

8.8
CVE-2019-12516

The slickquiz plugin through 1.3.7.1 for WordPress allows SQL Injection by Subscriber users, as demonstrated by a /wp-ad

8.8
CVE-2015-9395

The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.

8.8
CVE-2015-9398

The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection.

8.8
CVE-2015-9400

The wordpress-meta-robots plugin through 2.1 for WordPress has wp-admin/post-new.php text SQL injection.

8.8
CVE-2015-9446

The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.

8.8
CVE-2015-9448

The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid paramete

8.8
CVE-2019-16743

eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.

8.8
CVE-2019-16744

eBrigade before 5.0 has evenements.php cid SQL Injection.

8.8
CVE-2019-16745

eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection.

8.8
CVE-2019-12679

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

8.8
CVE-2019-12680

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

8.8
CVE-2019-12681

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

8.8
CVE-2019-12682

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

8.8
CVE-2019-12683

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

8.8
CVE-2019-12684

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

8.8
CVE-2019-12685

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

8.8
CVE-2019-12686

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started