Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 9/324
9.3
CVE-2026-59514

Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.

9.3
CVE-2026-59525

Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.

9.3
CVE-2026-59526

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

9.3
CVE-2026-61948

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

9.3
CVE-2026-61949

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

9.3
CVE-2026-61950

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

9.3
CVE-2026-59527

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

9.3
CVE-2026-59533

Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.

9.3
CVE-2026-59538

Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.

9.3
CVE-2026-59549

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

9.3
CVE-2026-59550

Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.

9.3
CVE-2026-65508

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

9.3
CVE-2026-65520

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

9.3
CVE-2026-65546

Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.

9.3
CVE-2026-66447

Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.

9.3
CVE-2026-66659

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome

9.3
CVE-2026-28001

Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.

9.3
CVE-2026-28142

Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.

9.3
CVE-2026-61966

Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.

9.3
CVE-2026-61969

Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.

9.3
CVE-2026-66436

Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.

9.3
CVE-2026-66446

Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.

9.3
CVE-2026-66458

Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.

9.3
CVE-2026-66472

Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.

9.3
CVE-2026-66478

Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.

9.3
CVE-2026-73187

Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.

9.3
CVE-2026-73339

Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.

9.3
CVE-2026-73355

Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.

9.3
CVE-2026-73365

Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.

9.3
CVE-2026-73392

Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.

9.3
CVE-2026-74015

Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

9.3
CVE-2026-73183

Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.

9.3
CVE-2026-73185

Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.

9.3
CVE-2026-73388

Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.

9.3
CVE-2026-73391

Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.

9.3
CVE-2025-15688

Unauthenticated SQL Injection in Capella <= 2.5.5 versions.

9.3
CVE-2026-66592

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.

9.3
CVE-2026-66593

Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.

9.3
CVE-2026-66609

Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.

9.3
CVE-2026-66649

Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.

9.3
CVE-2026-66680

Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.

9.3
CVE-2026-68566

Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.

9.3
CVE-2026-32551

Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.

9.3
CVE-2026-32554

Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.

9.3
CVE-2026-32555

Unauthenticated SQL Injection in Boost <= 2.0.4 versions.

9.3
CVE-2026-32479

Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.

9.3
CVE-2026-78260

Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.

9.3
CVE-2026-78288

Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.

9.1
CVE-2025-51567

A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote a

9.1
CVE-2021-47811

Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to mani

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started