Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 6/324
9.8
CVE-2026-51775

SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the applicati

9.8
CVE-2026-69240

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracl

9.8
CVE-2026-71207

The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its aut

9.8
CVE-2026-71231

IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decod

9.8
CVE-2026-71237

Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sa

9.8
CVE-2026-71248

Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw P

9.8
CVE-2026-5134

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Info

9.8
CVE-2026-67689

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or

9.8
CVE-2026-32227

SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to v

9.8
CVE-2026-72565

A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-tab

9.8
CVE-2026-63106

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the

9.8
CVE-2026-19425

Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated re

9.8
CVE-2026-72550

An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to ex

9.8
CVE-2026-72599

An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the ne

9.8
CVE-2026-46670

YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-imp

9.8
CVE-2026-73211

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolat

9.8
CVE-2026-48528

Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 th

9.8
CVE-2026-50769

The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based)

9.8
CVE-2026-67917

zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality.

9.8
CVE-2026-67854

SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code

9.8
CVE-2026-16019

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation

9.8
CVE-2026-63037

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi

9.8
CVE-2026-63038

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi

9.8
CVE-2026-63039

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi

9.8
CVE-2026-76904

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to v

9.8
CVE-2026-78568

The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due

9.8
CVE-2026-75330

The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerab

9.8
CVE-2026-75336

Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.

9.6
CVE-2026-42087

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.

9.6
CVE-2026-34260

SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacke

9.6
CVE-2026-53474

A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a s

9.6
CVE-2026-15062

SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allo

9.6
CVE-2026-73300

Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured

9.4
CVE-2025-67146

Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1)

9.4
CVE-2025-52025

An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backen

9.4
CVE-2026-26980

Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform

9.4
CVE-2026-37338

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.

9.4
CVE-2026-39109

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the

9.4
CVE-2024-46636

NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection v

9.4
CVE-2026-63221

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound v

9.3
CVE-2025-30633

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Nat

9.3
CVE-2025-68865

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility

9.3
CVE-2025-39484

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada all

9.3
CVE-2025-32303

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH

9.3
CVE-2025-23993

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Fr

9.3
CVE-2025-67928

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automot

9.3
CVE-2025-49055

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Le

9.3
CVE-2025-67945

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerL

9.3
CVE-2025-68034

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® Cleve

9.3
CVE-2025-68857

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ichurakov Paid Dow

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started