Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 60/324
CVE-2026-76602

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in l

CVE-2026-77994

Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Build

CVE-2026-77635

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective releas

CVE-2026-77137

The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged b

CVE-2026-54245

Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional a

CVE-2026-81672

SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video pa

CVE-2026-81673

The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. Th

CVE-2026-81674

The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized in

CVE-2026-81675

The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter.

CVE-2026-81676

A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenat

CVE-2026-81677

The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id

CVE-2026-74820

ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulne

CVE-2026-78612

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows

CVE-2026-78613

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an aut

CVE-2026-78614

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an a

CVE-2026-78070

Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Sav

CVE-2026-78072

Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1

CVE-2026-55509

WsgiDAV is a generic and extendable WebDAV server based on WSGI. Prior to 4.3.5, the sample MySQLBrowserProvider in wsgi

10.0
CVE-2024-55971

SQL Injection vulnerability in the default configuration of the Logitime WebClock application <= 5.43.0 allows an unauth

10.0
CVE-2024-13152

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy

10.0
CVE-2025-22954

GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl vi

10.0
CVE-2025-26852

DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.

10.0
CVE-2025-46337

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to

10.0
CVE-2025-4285

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Informati

10.0
CVE-2025-54119

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versi

10.0
CVE-2025-50567

Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replac

10.0
CVE-2025-57870

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes

10.0
CVE-2025-63689

Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e

10.0
CVE-2025-63531

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The

10.0
CVE-2024-57521

SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the creat

9.9
CVE-2025-24290

Multiple Authenticated SQL Injection vulnerabilities found in UISP Application (Version 2.4.206 and earlier) could allow

9.9
CVE-2025-55343

Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_d

9.8
CVE-2024-8855

The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a

9.8
CVE-2025-0455

The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to i

9.8
CVE-2024-57768

JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRo

9.8
CVE-2024-57031

WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.

9.8
CVE-2024-57034

WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.

9.8
CVE-2024-57035

WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.

9.8
CVE-2025-0585

The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject

9.8
CVE-2025-23218

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

9.8
CVE-2025-23219

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

9.8
CVE-2025-23220

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

9.8
CVE-2023-27112

pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the projectCode parameter at project.

9.8
CVE-2023-27113

pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the organizationCode parameter at pro

9.8
CVE-2023-37777

A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulner

9.8
CVE-2024-57328

A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises bec

9.8
CVE-2024-57665

JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability

9.8
CVE-2025-0929

SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete a

9.8
CVE-2025-22957

A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without an

9.8
CVE-2024-57098

Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started