CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19
Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacke
Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `p
rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior
An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of t
The WPRecovery plugin for WordPress is vulnerable to SQL Injection via the 'data[id]' parameter in all versions up to, a
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`,
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele
Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in
An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionari
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_r
An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition d
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules.
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiV
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listDa
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContr
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?ins
SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio
SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before
A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which a
Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject a
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab
A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within th
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Lif
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Hea
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the d
The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_i
Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craf
EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular p
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users
A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiSer
OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Stu
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Com
jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php.
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started