CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete
The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a
The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-base
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbit
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQ
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQ
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the
The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to
The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7
The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions u
The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' p
A vulnerability was determined in CRMEB up to 5.6.1. This vulnerability affects unknown code of the file /adminapi/expor
A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/pr
A flaw has been found in code-projects Intern Membership Management System 1.0. The impacted element is an unknown funct
A vulnerability has been found in code-projects Intern Membership Management System 1.0. This affects an unknown functio
A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of
A vulnerability was identified in code-projects Intern Membership Management System 1.0. Affected by this vulnerability
A security vulnerability has been detected in code-projects Intern Membership Management System 1.0. This issue affects
A vulnerability was detected in code-projects Intern Membership Management System 1.0. Impacted is an unknown function o
A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function
A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function
A vulnerability was identified in iomad up to 5.0. Affected is an unknown function of the component Company Admin Block.
A security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unkn
A vulnerability was determined in itsourcecode News Portal Project 1.0. This affects an unknown part of the file /admin/
A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the fil
A vulnerability has been found in itsourcecode College Management System 1.0. This vulnerability affects unknown code of
A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of t
A security vulnerability has been detected in code-projects Simple Flight Ticket Booking System 1.0. This impacts an unk
A vulnerability was detected in code-projects Simple Flight Ticket Booking System 1.0. Affected is an unknown function o
A vulnerability was detected in SourceCodester Employee Task Management System 1.0. Impacted is an unknown function of t
A flaw has been found in SourceCodester Employee Task Management System up to 1.0. The affected element is an unknown fu
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
A vulnerability was detected in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This affects t
A flaw has been found in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This vulnerability af
A weakness has been identified in phpipam up to 1.7.4. The impacted element is an unknown function of the file app/admin
A vulnerability has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing
A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability i
A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is s
A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of
A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown proce
A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of
A weakness has been identified in YunaiV yudao-cloud up to 2026.01. This vulnerability affects unknown code of the file
A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the fil
A vulnerability was identified in PHPGurukul News Portal Project 4.1. This issue affects some unknown processing of the
A security flaw has been discovered in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /
SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_a
CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be
A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of th
A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of t
A vulnerability has been found in likeadmin-likeshop likeadmin_php up to 1.9.6. Affected by this issue is the function q
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started