CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function dele
A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function delete_category of
A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unkn
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerabilit
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_user of the file /a
A vulnerability was found in code-projects Gym Management System 1.0. Affected by this vulnerability is an unknown funct
A vulnerability was determined in itsourcecode Courier Management System 1.0. Affected is an unknown function of the fil
A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected is an unknown function of the file
A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file
A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admi
A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function dele
A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown
A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function ac
A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Adminis
A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the
A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of t
A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::exec
A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the fi
A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processin
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 1
A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore driv
A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of
A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the
A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing o
HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att
IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to
SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-sup
The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter befor
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta
An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerabl
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to imp
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the "ad
When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access
The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values be
The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements
Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit p
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table cre
The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a S
Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a
SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user
A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by
Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/classes/Master.php?f=de
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started