Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 305/324
9.8
CVE-2018-6576

SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.

9.8
CVE-2018-6577

SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&ta

9.8
CVE-2018-6578

SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task

9.8
CVE-2018-6579

SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.

9.8
CVE-2018-6581

SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username par

9.8
CVE-2018-6582

SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, ge

9.8
CVE-2018-6604

SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail

9.8
CVE-2018-6605

SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, get

9.8
CVE-2018-6609

SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit acti

9.8
CVE-2017-17412

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17413

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17414

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17415

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17416

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17417

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17418

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17419

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17420

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17421

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17422

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17423

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17424

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17425

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17652

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17653

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17654

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17655

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17656

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17657

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17658

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2017-17659

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu

9.8
CVE-2018-1000044

Security Onion Solutions Squert version 1.1.1 through 1.6.7 contains a SQL Injection vulnerability in .inc/callback.php

9.8
CVE-2018-6863

SQL Injection exists in PHP Scripts Mall Select Your College Script 2.0.2 via a Login Parameter.

9.8
CVE-2018-6893

controllers/member/Api.php in dayrui FineCms 5.2.0 has SQL Injection: a request with s=member,c=api,m=checktitle, and th

9.8
CVE-2018-6928

PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term.

9.8
CVE-2017-5810

A remote sql injection vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

9.8
CVE-2017-5814

A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were f

9.8
CVE-2018-5970

SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries paramete

9.8
CVE-2018-5971

SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array paramet

9.8
CVE-2018-5974

SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter.

9.8
CVE-2018-5975

SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI.

9.8
CVE-2018-5980

SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action.

9.8
CVE-2018-5981

SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.

9.8
CVE-2018-5982

SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= requ

9.8
CVE-2018-5983

SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request.

9.8
CVE-2018-5987

SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id paramete

9.8
CVE-2018-5989

SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber actio

9.8
CVE-2018-5990

SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter.

9.8
CVE-2018-5991

SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats re

9.8
CVE-2018-5992

SQL Injection exists in the Staff Master through 1.0 RC 1 component for Joomla! via the name parameter in a view=staff r

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started