CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view u
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view d
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _RemoveRequest funct
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DeleteSysLogEntry fu
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the view.html.php files
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the admin.mbnetj.php fil
In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to l
SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscrib
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField``
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject
A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of use
A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0. The vulnerability is located i
The Attendance Manager plugin for WordPress is vulnerable to SQL Injection via the 'attmgr_off' parameter in all version
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiN
SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate fi
OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise ed
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due t
A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of t
Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of v
Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 befo
OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration
Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrder
A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/tex
MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `m
Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context han
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed
SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the Prod
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a
The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algor
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind S
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage conne
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 an
The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restr
In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comme
A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. This affects the function _checkValForAPI of the file h
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to SQL Injection via the 'params' paramet
CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in
The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'c
An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a pro
The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in
The WP-ClanWars plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, a
The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' para
The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-based SQL Injection via the ‘referencedI
mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vul
The Mail Mint plugin for WordPress is vulnerable to blind SQL Injection via the 'forms', 'automation', 'email/templates'
The Bookster – WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘raw’ pa
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started