Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 5/324
9.8
CVE-2026-13766

DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL buil

9.8
CVE-2026-8402

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electroni

9.8
CVE-2026-57517

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote atta

9.8
CVE-2026-34099

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): S

9.8
CVE-2026-58521

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun

9.8
CVE-2026-14363

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun

9.8
CVE-2026-52186

SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary cod

9.8
CVE-2026-4321

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web

9.8
CVE-2026-8307

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Desig

9.8
CVE-2026-5955

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software an

9.8
CVE-2026-2397

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automa

9.8
CVE-2026-5801

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics

9.8
CVE-2026-60090

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowled

9.8
CVE-2026-51821

SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitra

9.8
CVE-2026-62390

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A ba

9.8
CVE-2026-38158

A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to acc

9.8
CVE-2026-8297

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics En

9.8
CVE-2026-52348

cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.

9.8
CVE-2026-57308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. A

9.8
CVE-2026-1617

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communica

9.8
CVE-2016-20096

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows r

9.8
CVE-2026-52469

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.

9.8
CVE-2026-52470

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper

9.8
CVE-2026-52472

SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml

9.8
CVE-2026-2395

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Info

9.8
CVE-2026-63359

The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated att

9.8
CVE-2026-16462

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker

9.8
CVE-2026-54658

Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/u

9.8
CVE-2026-65890

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthe

9.8
CVE-2025-65340

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.

9.8
CVE-2025-67403

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the paramete

9.8
CVE-2025-67404

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters

9.8
CVE-2025-69942

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.

9.8
CVE-2025-69943

kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and

9.8
CVE-2026-17543

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions f

9.8
CVE-2026-4978

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffi

9.8
CVE-2025-65336

Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.

9.8
CVE-2025-69930

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.

9.8
CVE-2025-69931

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.

9.8
CVE-2025-69933

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

9.8
CVE-2025-69934

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

9.8
CVE-2025-69935

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via th

9.8
CVE-2025-69936

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

9.8
CVE-2025-69937

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Paramete

9.8
CVE-2025-69938

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.

9.8
CVE-2025-69941

SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.

9.8
CVE-2025-69947

SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.

9.8
CVE-2025-69946

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters distr

9.8
CVE-2025-69948

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.

9.8
CVE-2026-65321

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrar

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started