Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 39/324
7.3
CVE-2026-77020

A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is a

7.3
CVE-2026-78143

A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknow

7.3
CVE-2026-78171

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unkn

7.3
CVE-2026-78182

A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System

7.3
CVE-2026-78197

A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unkn

7.3
CVE-2026-78198

A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects

7.3
CVE-2026-78199

A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function o

7.3
CVE-2026-78201

A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the fil

7.3
CVE-2026-78244

A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown f

7.3
CVE-2026-78246

A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown c

7.3
CVE-2026-78247

A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown proc

7.3
CVE-2026-78248

A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function

7.3
CVE-2026-79804

A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affec

7.3
CVE-2026-79845

A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of

7.3
CVE-2026-81203

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown functio

7.3
CVE-2026-82600

A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the fi

7.2
CVE-2026-21856

The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to commit 9bdb3a75a98a7047b6d70144eb1da1655d6992

7.2
CVE-2025-59922

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi

7.2
CVE-2025-37181

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re

7.2
CVE-2025-37182

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re

7.2
CVE-2025-37183

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re

7.2
CVE-2026-23723

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an authenticated SQL Injection vulnerability was ide

7.2
CVE-2025-59473

SQL Injection vulnerability in the Structure for Admin authenticated user

7.2
CVE-2025-70397

jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

7.2
CVE-2025-50188

Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d

7.2
CVE-2025-50191

Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFi

7.2
CVE-2026-26892

Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.

7.2
CVE-2026-33133

WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL

7.2
CVE-2026-2279

The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all

7.2
CVE-2026-33539

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version

7.2
CVE-2026-33910

OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to

7.2
CVE-2026-33914

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio

7.2
CVE-2026-33503

Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the Li

7.2
CVE-2026-33504

Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2

7.2
CVE-2026-33505

Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelat

7.2
CVE-2026-27834

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability e

7.2
CVE-2026-27885

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability w

7.2
CVE-2026-29047

GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user

7.2
CVE-2026-39325

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en

7.2
CVE-2026-39343

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEv

7.2
CVE-2026-4112

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series applian

7.2
CVE-2025-61848

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA

7.2
CVE-2026-33714

Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in

7.2
CVE-2026-37341

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_ca

7.2
CVE-2026-37342

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_park

7.2
CVE-2026-37343

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_us

7.2
CVE-2026-37344

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_lo

7.2
CVE-2026-40871

mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-or

7.2
CVE-2026-7435

SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed

7.2
CVE-2026-41641

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started