Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 63/324
9.8
CVE-2025-40621

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to ob

9.8
CVE-2025-40622

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to ob

9.8
CVE-2025-40623

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to ob

9.8
CVE-2025-40624

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to ob

9.8
CVE-2025-44073

SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.

9.8
CVE-2025-0668

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve

9.8
CVE-2025-46828

WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in ve

9.8
CVE-2025-45885

PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Att

9.8
CVE-2025-46188

SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.

9.8
CVE-2025-46189

SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php vi

9.8
CVE-2025-46190

SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the

9.8
CVE-2025-46192

SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the o

9.8
CVE-2025-4559

The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arb

9.8
CVE-2025-44830

EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.

9.8
CVE-2023-49641

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter

9.8
CVE-2025-26390

A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of af

9.8
CVE-2025-44831

EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.

9.8
CVE-2025-28056

rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.

9.8
CVE-2025-46052

An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command an

9.8
CVE-2024-6159

The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a para

9.8
CVE-2024-6809

The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using

9.8
CVE-2025-32814

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

9.8
CVE-2024-51101

PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerabil

9.8
CVE-2025-40665

Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update a

9.8
CVE-2025-40666

Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update a

9.8
CVE-2025-48949

Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulner

9.8
CVE-2025-1750

An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12

9.8
CVE-2025-4578

The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a

9.8
CVE-2025-1793

Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These v

9.8
CVE-2025-40654

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c

9.8
CVE-2025-40655

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c

9.8
CVE-2025-40656

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c

9.8
CVE-2025-40657

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c

9.8
CVE-2024-56158

XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGE

9.8
CVE-2025-6169

The WIMP website co-construction management platform from HAMASTAR Technology has a SQL Injection vulnerability, allowin

9.8
CVE-2025-26198

CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The

9.8
CVE-2025-52474

WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, a SQL Injection vulnerability was identified

9.8
CVE-2025-4738

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yirmibes Software

9.8
CVE-2025-46179

A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx pa

9.8
CVE-2025-46101

SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model

9.8
CVE-2021-41691

A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TR

9.8
CVE-2015-0842

yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.

9.8
CVE-2025-53091

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Time-Based Bl

9.8
CVE-2024-11739

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics C

9.8
CVE-2024-12143

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobilteg Mobile In

9.8
CVE-2024-12150

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eron Software Woww

9.8
CVE-2024-12364

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Softwar

9.8
CVE-2025-40731

SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to retrieve, create, up

9.8
CVE-2025-28983

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Cli

9.8
CVE-2025-45065

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the lo

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started