Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 71/324
8.8
CVE-2025-32867

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v

8.8
CVE-2025-32868

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v

8.8
CVE-2025-32869

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v

8.8
CVE-2025-32870

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v

8.8
CVE-2025-32871

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v

8.8
CVE-2025-32872

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v

8.8
CVE-2025-23176

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

8.8
CVE-2025-32968

XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it

8.8
CVE-2025-45956

A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows a

8.8
CVE-2025-45321

kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.ph

8.8
CVE-2025-45322

kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the

8.8
CVE-2024-11267

The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL sta

8.8
CVE-2024-52874

In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.

8.8
CVE-2024-13955

2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if a

8.8
CVE-2025-48998

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the p

8.8
CVE-2023-2921

The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL st

8.8
CVE-2025-29892

An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow re

8.8
CVE-2025-47172

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allo

8.8
CVE-2025-40728

SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retr

8.8
CVE-2025-49215

A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to e

8.8
CVE-2025-46109

SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information vi

8.8
CVE-2025-5590

The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all

8.8
CVE-2025-40735

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injec

8.8
CVE-2025-52577

A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServl

8.8
CVE-2025-53475

A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through Network

8.8
CVE-2025-53515

A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServle

8.8
CVE-2025-53823

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior

8.8
CVE-2025-53946

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

8.8
CVE-2025-54058

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

8.8
CVE-2025-54060

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

8.8
CVE-2025-54061

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

8.8
CVE-2025-54062

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

8.8
CVE-2025-54079

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

8.8
CVE-2025-50585

StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.

8.8
CVE-2025-41370

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The

8.8
CVE-2025-41371

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The

8.8
CVE-2025-41372

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The

8.8
CVE-2025-41373

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The

8.8
CVE-2025-41374

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The

8.8
CVE-2013-10044

An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to

8.8
CVE-2025-54788

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions an

8.8
CVE-2023-41520

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassA

8.8
CVE-2023-41521

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessio

8.8
CVE-2023-41522

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStuden

8.8
CVE-2023-41523

Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress par

8.8
CVE-2023-41524

Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username paramet

8.8
CVE-2023-41531

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the user

8.8
CVE-2023-41532

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter i

8.8
CVE-2025-52914

A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could a

8.8
CVE-2025-47954

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started