Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 7/324
9.3
CVE-2025-69295

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven

9.3
CVE-2025-69304

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Allma

9.3
CVE-2025-69305

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Crete

9.3
CVE-2025-69306

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Elect

9.3
CVE-2025-69307

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Medin

9.3
CVE-2025-69308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Nestb

9.3
CVE-2025-69309

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Saasp

9.3
CVE-2025-69310

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Woodl

9.3
CVE-2025-69337

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Wolmart

9.3
CVE-2025-69365

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Uroan

9.3
CVE-2025-69366

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Emerc

9.3
CVE-2026-24956

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download

9.3
CVE-2025-69338

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Riode C

9.3
CVE-2026-28115

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attracti

9.3
CVE-2026-27413

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile

9.3
CVE-2026-33134

WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vuln

9.3
CVE-2026-22484

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Co

9.3
CVE-2026-24993

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced

9.3
CVE-2026-25340

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonste

9.3
CVE-2026-25371

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise

9.3
CVE-2026-25377

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobse

9.3
CVE-2026-31920

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTec

9.3
CVE-2026-32499

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatB

9.3
CVE-2026-32539

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress Publi

9.3
CVE-2026-22336

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Bookin

9.3
CVE-2026-40797

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC We

9.3
CVE-2026-39531

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W

9.3
CVE-2026-42773

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOn

9.3
CVE-2026-42774

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngi

9.3
CVE-2026-42727

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active

9.3
CVE-2026-42740

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan

9.3
CVE-2026-42747

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Eas

9.3
CVE-2026-42755

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn

9.3
CVE-2026-42761

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active

9.3
CVE-2026-42672

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W

9.3
CVE-2026-42684

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Porta

9.3
CVE-2026-39494

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Produc

9.3
CVE-2026-42647

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport

9.3
CVE-2026-39441

Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.

9.3
CVE-2026-39492

Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.

9.3
CVE-2026-39493

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.

9.3
CVE-2026-39502

Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.

9.3
CVE-2026-39511

Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.

9.3
CVE-2026-39512

Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.

9.3
CVE-2026-39519

Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.

9.3
CVE-2026-39530

Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.

9.3
CVE-2026-40771

Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.

9.3
CVE-2026-40798

Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.

9.3
CVE-2026-42381

Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.

9.3
CVE-2026-42386

Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started