Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 8/324
9.3
CVE-2026-42639

Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.

9.3
CVE-2026-42665

Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.

9.3
CVE-2026-45439

Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.

9.3
CVE-2026-48886

Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.

9.3
CVE-2026-49067

Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.

9.3
CVE-2026-49776

Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websit

9.3
CVE-2026-52693

Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.

9.3
CVE-2026-39574

Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.

9.3
CVE-2026-49772

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / Stell

9.3
CVE-2026-52715

Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.

9.3
CVE-2026-22332

Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.

9.3
CVE-2026-22340

Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.

9.3
CVE-2026-39438

Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.

9.3
CVE-2026-39596

Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.

9.3
CVE-2026-48875

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.

9.3
CVE-2026-49076

Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.

9.3
CVE-2026-49079

Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions.

9.3
CVE-2026-49080

Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.

9.3
CVE-2026-49084

Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.

9.3
CVE-2026-54186

Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.

9.3
CVE-2026-54187

Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.

9.3
CVE-2026-54811

Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.

9.3
CVE-2025-59554

Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.

9.3
CVE-2026-54808

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Trave

9.3
CVE-2026-54809

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U

9.3
CVE-2026-54815

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shi

9.3
CVE-2026-54819

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listd

9.3
CVE-2026-54812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Mot

9.3
CVE-2026-54836

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows

9.3
CVE-2026-54843

Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.

9.3
CVE-2026-54849

Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.

9.3
CVE-2026-54820

Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

9.3
CVE-2026-54825

Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

9.3
CVE-2026-54827

Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.

9.3
CVE-2026-54831

Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.

9.3
CVE-2026-56034

Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.

9.3
CVE-2026-56036

Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.

9.3
CVE-2026-56062

Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.

9.3
CVE-2026-56067

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.

9.3
CVE-2026-56068

Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.

9.3
CVE-2026-56070

Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.

9.3
CVE-2026-55721

Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debu

9.3
CVE-2026-57679

Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.

9.3
CVE-2026-57683

Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.

9.3
CVE-2026-57702

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture

9.3
CVE-2026-57707

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simpl

9.3
CVE-2026-57714

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoin

9.3
CVE-2026-57726

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirk

9.3
CVE-2026-57739

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newslet

9.3
CVE-2026-59515

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-cop

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started