CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to ob
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to ob
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to ob
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to ob
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve
WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in ve
PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Att
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php vi
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the o
The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arb
EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter
A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of af
EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.
rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.
An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command an
The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a para
The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using
An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.
PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerabil
Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update a
Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update a
Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulner
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12
The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a
Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These v
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c
XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGE
The WIMP website co-construction management platform from HAMASTAR Technology has a SQL Injection vulnerability, allowin
CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The
WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, a SQL Injection vulnerability was identified
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yirmibes Software
A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx pa
SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TR
yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Time-Based Bl
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics C
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobilteg Mobile In
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eron Software Woww
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Softwar
SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to retrieve, create, up
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Cli
employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the lo
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started