CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is a
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknow
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unkn
A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unkn
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects
A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function o
A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the fil
A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown f
A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown c
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown proc
A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function
A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affec
A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown functio
A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the fi
The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to commit 9bdb3a75a98a7047b6d70144eb1da1655d6992
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an authenticated SQL Injection vulnerability was ide
SQL Injection vulnerability in the Structure for Admin authenticated user
jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.
Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d
Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFi
Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.
WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL
The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the Li
Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2
Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelat
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability e
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability w
GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en
ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEv
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series applian
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA
Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_ca
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_park
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_us
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_lo
mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-or
SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started