Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 42/324
7.1
CVE-2026-65494

Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.

7.1
CVE-2026-71276

Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transpor

7.1
CVE-2026-72731

Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-l

7.1
CVE-2026-72607

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta

7.1
CVE-2026-72609

An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff wit

7.1
CVE-2026-73331

CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post cr

7.1
CVE-2026-19680

A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from th

7.1
CVE-2026-73345

Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.

7.1
CVE-2026-56088

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an

7.0
CVE-2026-32611

Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL inject

6.8
CVE-2025-14973

The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a

6.8
CVE-2025-15441

The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping"

6.8
CVE-2026-9617

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and p

6.8
CVE-2026-12283

Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard

6.8
CVE-2026-15153

The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative

6.8
CVE-2026-14872

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and e

6.8
CVE-2026-14601

The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in

6.8
CVE-2026-16959

The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it in

6.7
CVE-2026-22596

Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabili

6.7
CVE-2024-14025

An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who

6.7
CVE-2025-62846

An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, th

6.7
CVE-2026-39809

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiCl

6.7
CVE-2026-32167

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized

6.7
CVE-2026-32176

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized

6.6
CVE-2026-27768

SQL Injection affecting the Access Manager role.

6.5
CVE-2025-15238

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate

6.5
CVE-2025-15239

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate

6.5
CVE-2025-13652

The CBX Bookmark & Favorite plugin for WordPress is vulnerable to generic SQL Injection via the ‘orderby’ parameter in a

6.5
CVE-2025-14153

The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the '

6.5
CVE-2025-9318

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injec

6.5
CVE-2025-67811

Area9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient in

6.5
CVE-2025-51626

SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint.

6.5
CVE-2022-50894

VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate d

6.5
CVE-2025-67082

An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" para

6.5
CVE-2025-67261

Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in t

6.5
CVE-2026-0683

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via the

6.5
CVE-2025-70311

JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 paramet

6.5
CVE-2026-22044

GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can

6.5
CVE-2026-24419

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e

6.5
CVE-2025-69216

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an au

6.5
CVE-2026-24416

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e

6.5
CVE-2026-24417

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e

6.5
CVE-2026-24418

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e

6.5
CVE-2025-15477

The Bucketlister plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode `category` and `id` attr

6.5
CVE-2026-2235

C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar

6.5
CVE-2026-1602

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar

6.5
CVE-2025-13431

The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the ‘args’ parameter in all ve

6.5
CVE-2019-25320

E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard with

6.5
CVE-2026-1639

The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to time-based blind

6.5
CVE-2026-1317

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versi

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started