Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 45/324
6.5
CVE-2026-63080

Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authe

6.5
CVE-2026-13009

The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param

6.5
CVE-2026-13119

The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan

6.5
CVE-2026-15448

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order

6.5
CVE-2026-15761

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event

6.5
CVE-2026-15906

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via th

6.5
CVE-2026-65707

Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract ar

6.5
CVE-2026-6251

The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and i

6.5
CVE-2026-15267

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL

6.5
CVE-2026-15304

The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions

6.5
CVE-2026-16092

The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field vi

6.5
CVE-2026-14554

The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them

6.5
CVE-2026-16087

The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injec

6.5
CVE-2026-6453

The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. Thi

6.5
CVE-2026-18737

Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL

6.5
CVE-2026-69704

Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsan

6.5
CVE-2026-11421

The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Inje

6.5
CVE-2026-15941

The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches f

6.5
CVE-2026-49004

The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabi

6.5
CVE-2026-11977

The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to

6.5
CVE-2026-15281

The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w

6.5
CVE-2026-71282

ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpol

6.5
CVE-2026-16065

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV fil

6.5
CVE-2026-72908

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template

6.5
CVE-2026-72608

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta

6.5
CVE-2026-17419

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutraliza

6.5
CVE-2026-16810

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is v

6.5
CVE-2026-16080

The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' paramete

6.5
CVE-2026-15453

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via

6.5
CVE-2026-16586

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Secon

6.5
CVE-2026-18387

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection

6.5
CVE-2026-12248

The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in all version

6.5
CVE-2026-15963

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injectio

6.5
CVE-2026-16079

The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content

6.5
CVE-2026-9767

The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'or

6.5
CVE-2026-20327

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated,

6.5
CVE-2026-76343

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

6.5
CVE-2026-76364

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Str

6.5
CVE-2026-15023

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection

6.5
CVE-2026-78470

The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0

6.5
CVE-2026-78468

The FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plug

6.5
CVE-2026-46370

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels

6.5
CVE-2026-46371

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple M

6.5
CVE-2026-49809

Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used i

6.5
CVE-2026-55855

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to

6.4
CVE-2026-27684

SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacke

6.4
CVE-2026-5372

An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This

6.4
CVE-2026-3346

IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows

6.4
CVE-2026-11945

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON docume

6.4
CVE-2026-11321

The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started