CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability was identified in Daptin 0.10.3. Affected by this vulnerability is the function goqu.L of the file serve
A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected by this v
A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown part of the file /
A weakness has been identified in code-projects Online Product Reservation System 1.0. This issue affects some unknown p
A vulnerability was determined in code-projects Online Product Reservation System 1.0. The affected element is an unknow
A vulnerability was identified in code-projects Online Product Reservation System 1.0. The impacted element is an unknow
A flaw has been found in Campcodes Supplier Management System 1.0. Affected by this issue is some unknown functionality
A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown functi
A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file s
A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the
A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/
A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSys
A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/
A vulnerability has been found in jiujiujia/victor123/wxw850227 jjjfood and jjjshop_food up to 20260103. This vulnerabil
A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file
A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillI
Tanium addressed a SQL injection vulnerability in Asset.
A weakness has been identified in itsourcecode School Management System 1.0. This affects an unknown part of the file /r
A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_In
A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/ap
Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may r
Tanium addressed an improper input validation vulnerability in Discover.
A security flaw has been discovered in Xiaopi Panel up to 20260126. This impacts an unknown function of the file /demo.p
A security vulnerability has been detected in code-projects Contact Management System 1.0. This issue affects some unkno
A security flaw has been discovered in tushar-2223 Hotel-Management-System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d1
A security vulnerability has been detected in Alixhan xh-admin-backend up to 1.7.0. This issue affects some unknown proc
A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an u
A flaw has been found in code-projects Patient Record Management System 1.0. This affects an unknown function of the fil
Tanium addressed a SQL injection vulnerability in Asset.
A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the
A vulnerability was determined in Jinher OA C6 up to 20260210. This issue affects some unknown processing of the file /C
A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProje
A weakness has been identified in itsourcecode College Management System 1.0. Affected by this issue is some unknown fun
A security vulnerability has been detected in itsourcecode College Management System 1.0. This affects an unknown part o
A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the
A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frph
A vulnerability was detected in DefaultFuction Jeson Customer Relationship Management System 1.0.0. Impacted is an unkno
A vulnerability has been found in JeecgBoot up to 3.9.1. Affected is the function isExistSqlInjectKeyword of the file /j
A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.p
A vulnerability has been found in SourceCodester Sales and Inventory System up to 1.0. The impacted element is an unknow
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the
A vulnerability was identified in SourceCodester Sales and Inventory System up to 1.0. Affected is an unknown function o
A weakness has been identified in itsourcecode sanitize or validate this input 1.0. Affected is an unknown function of t
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. This vulnerability affects unknow
A vulnerability was identified in EasyCMS up to 1.6. The affected element is an unknown function of the file /RbacnodeAc
A security flaw has been discovered in EasyCMS up to 1.6. The impacted element is an unknown function of the file /Rbacu
A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown fun
A vulnerability has been found in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file pur
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started