Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 61/324
9.8
CVE-2025-24905

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio

9.8
CVE-2025-24906

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio

9.8
CVE-2025-24957

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio

9.8
CVE-2020-36084

SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql que

9.8
CVE-2024-57430

An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers

9.8
CVE-2025-22992

A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerabili

9.8
CVE-2025-25349

PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem pa

9.8
CVE-2025-25351

PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense

9.8
CVE-2025-25388

A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which all

9.8
CVE-2025-25389

A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allow

9.8
CVE-2025-25221

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection v

9.8
CVE-2025-25222

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection v

9.8
CVE-2025-1023

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploit

9.8
CVE-2024-55460

A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election Syste

9.8
CVE-2025-26606

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab

9.8
CVE-2025-26607

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab

9.8
CVE-2025-26608

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab

9.8
CVE-2025-26609

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab

9.8
CVE-2025-26610

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab

9.8
CVE-2025-26611

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab

9.8
CVE-2025-26612

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab

9.8
CVE-2025-26617

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab

9.8
CVE-2025-27096

WeGIA is a Web Manager for Institutions with a focus on Portuguese language. A SQL Injection vulnerability was discovere

9.8
CVE-2024-54820

XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login

9.8
CVE-2025-25513

Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.

9.8
CVE-2024-53544

NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability

9.8
CVE-2025-22974

SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTra

9.8
CVE-2025-27135

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL i

9.8
CVE-2025-25516

Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.

9.8
CVE-2025-25517

Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.

9.8
CVE-2025-25519

Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.

9.8
CVE-2025-25520

Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.

9.8
CVE-2025-25521

Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.

9.8
CVE-2025-1751

A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker t

9.8
CVE-2024-13148

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter

9.8
CVE-2024-55160

GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/op

9.8
CVE-2025-1869

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/c

9.8
CVE-2025-1870

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in

9.8
CVE-2025-1871

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" pa

9.8
CVE-2025-1872

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in a

9.8
CVE-2025-1873

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescriptio

9.8
CVE-2025-1874

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admi

9.8
CVE-2025-1875

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in sear

9.8
CVE-2024-50706

Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbi

9.8
CVE-2025-26136

A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.

9.8
CVE-2025-27640

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows SQL Injection

9.8
CVE-2025-27659

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows SQL Injection O

9.8
CVE-2024-12097

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Boceksoft Informat

9.8
CVE-2024-13147

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2

9.8
CVE-2024-12144

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Finder Fire Safety

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started