CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file
A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown
A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /ch
A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the f
A vulnerability has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the fi
A vulnerability was found in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown f
A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function
A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi
A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /
A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the f
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is so
A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the functio
A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /view
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unkn
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file
A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impact
A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affe
A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affect
A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of
A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function
A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the
A vulnerability was found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /p
A vulnerability was determined in liketrek TREK up to 3.0.22. The affected element is the function journeyService.update
With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logi
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processin
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of t
A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknow
A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unkn
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the fi
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the fi
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA
A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions), blu
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, an authenticated user with columnAdd perm
Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attac
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead t
SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field dat
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in p
KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constru
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th
The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific
A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/in
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started