CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it
A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows a
kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.ph
kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the
The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL sta
In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.
2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if a
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the p
The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL st
An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow re
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allo
SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retr
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to e
SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information vi
The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injec
A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServl
A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through Network
A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServle
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection
StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The
An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions an
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassA
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessio
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStuden
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress par
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username paramet
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the user
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter i
A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could a
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started