CWE-89
MITRE ↗Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote a
Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to mani
Frequently Asked Questions
What is CWE-89?
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-89?
There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.
How can I protect against CWE-89 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.
Detect CWE-89 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.
Get Started