CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code
A weakness has been identified in SourceCodester/janobe Resort Reservation System 1.0. This issue affects some unknown p
A flaw has been found in CodePhiliaX Chat2DB up to 0.3.7. This vulnerability affects the function exportTable/exportTabl
A vulnerability has been found in vanna-ai vanna up to 2.0.2. Affected is the function update_sql of the file src/vanna/
A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddControll
A vulnerability was identified in itsourcecode College Management System 1.0. The impacted element is an unknown functio
A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability a
A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown functio
A vulnerability was determined in Mindinventory MindSQL up to 0.2.1. The affected element is the function ask_db of the
A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the fi
A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown fu
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the
A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the
A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is
A weakness has been identified in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown
A security vulnerability has been detected in SourceCodester Simple E-learning System 1.0. This affects an unknown part
A vulnerability was detected in SourceCodester Simple E-learning System 1.0. This vulnerability affects unknown code of
A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the f
A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. Impacted is the function selectAll of the
A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown proc
A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of th
A weakness has been identified in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code
A security vulnerability has been detected in SourceCodester Sales and Inventory System 1.0. This issue affects some unk
A vulnerability was detected in SourceCodester Sales and Inventory System 1.0. Impacted is an unknown function of the fi
A flaw has been found in SourceCodester Sales and Inventory System 1.0. The affected element is an unknown function of t
A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown functio
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file /up
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code
A vulnerability was detected in code-projects Accounting System 1.0. The affected element is an unknown function of the
A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown fun
A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/m
A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /ad
A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the
A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the fi
A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of
A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects
A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted e
A security vulnerability has been detected in halex CourseSEL up to 1.1.0. Affected by this vulnerability is the functio
A vulnerability was identified in PHPGurukul User Registration & Login and User Management System 3.3. The affected elem
A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown process
A vulnerability was identified in itsourcecode Online Cellphone System 1.0. Affected by this vulnerability is an unknown
A flaw has been found in PHPGurukul PHPGurukul Online Shopping Portal Project up to 2.1. Impacted is an unknown function
A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function
A security flaw has been discovered in AutohomeCorp frostmourne up to 1.0. Affected is the function httpTest of the file
A vulnerability was found in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /Online
A vulnerability was determined in CodeAstro Online Classroom 1.0. This issue affects some unknown processing of the file
A vulnerability was identified in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineCla
A security vulnerability has been detected in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown par
A vulnerability was determined in zhongyu09 openchatbi up to 0.2.1. The impacted element is an unknown function of the c
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started