CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create
SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input valid
Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an
A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system. An unauthe
SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attack
In the "CheckUnitCodeAndKey.pl" service, the "validateOrgUnit" function is vulnerable to SQL injection.
A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to injec
SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through
SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete d
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiS
SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which co
Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there i
Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability e
ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::ge
SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve,
OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that a
An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled
SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/ge
Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exist
Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 throu
Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 throu
Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzySearch in server/resource/resource_finda
Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and u
Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/gr
Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose record
A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL c
EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in
ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #122, there is a critical SQL Injection (SQLi)
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated
The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading
NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the
SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'mo
A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multip
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web ap
SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inj
SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/u
Backend users with write access to the form_definition database table were able to directly create, update, or delete fo
Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Inject
An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" m
UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to inte
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with column-create
Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline. The vulnerability allows a remote,
An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/inde
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injecti
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed
SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all right
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent`
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAge
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started