CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerab
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitr
CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities
SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitra
Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.
OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to exe
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passe
Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vu
Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists th
A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators t
The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL sta
The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parame
Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib
baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administ
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with admin
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with admin
A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within applicat
Kmaleon 1.1.0.205 contains an authenticated SQL injection vulnerability in the 'tipocomb' parameter of kmaleonW.php that
SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authen
LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows rem
TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumer
Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database informat
PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers
PhpIX 2012 Professional contains a SQL injection vulnerability in the 'id' parameter of product_detail.php that allows r
GUnet OpenEclass 1.7.3 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate
Fishing Reservation System 7.5 contains multiple remote SQL injection vulnerabilities in admin.php, cart.php, and calend
RimbaLinux AhadPOS 1.11 contains a SQL injection vulnerability in the 'alamatCustomer' parameter that allows attackers t
thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries th
TheJshen ContentManagementSystem 1.04 contains a SQL injection vulnerability that allows attackers to manipulate databas
ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers
eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows atta
PHPads 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL querie
Tradebox 5.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries
Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitr
Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL querie
Facturation System 1.0 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary
Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by
Placeto CMS Alpha rv.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate databas
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents
ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpo
Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queri
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `o
Meeplace Business Review Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute
School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows at
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started