CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country pa
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid para
Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTT
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum para
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, ass
SQL injection vulnerability in Password Recovery in GPWeb 8.4.61 allows remote attackers to execute arbitrary SQL comman
Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Prof
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
Readymade Video Sharing Script has SQL Injection via the viewsubs.php chnlid parameter or the search_video.php search pa
Readymade Job Site Script has SQL Injection via the location_name array parameter to the /job URI.
SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute a
SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers
SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbi
PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter.
PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter.
PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username parameter.
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows re
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started