Skip to main content

About CWE-89

Because databases often hold sensitive data, disclosure is frequent. Attackers may also alter or delete records, log in as another user, change authorization data, and in some setups execute system commands.

MITRE name
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Stable
Also known as
SQL injection, SQLi

Mitigations

  • +Use prepared statements, parameterized queries or stored procedures that keep data apart from the query.
  • +Avoid building and executing query strings dynamically inside stored procedures.
  • +Use a vetted persistence framework that handles quoting and encoding correctly.
  • +Run database connections with the least privilege required and use the strictest permissions on database objects.
  • +Repeat client-side checks on the server.

Detection
Automated static analysis can often detect it using data flow analysis, and dynamic testing with diverse inputs such as fuzzing can also reveal it.

CWE-89 Vulnerabilities

20 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-9586
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
Sangoma9.319.0%KEV2026-07-17
CVE-2026-72898
Metabase SQL injection via password reset endpoint
Metabase10.019.0%KEV2026-08-10
CVE-2026-9082
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
Drupal9.815.7%KEV2026-05-20
CVE-2026-42208
LiteLLM: SQL injection in Proxy API key verification
BerriAI9.35.8%KEV2026-05-08
CVE-2026-21643
Fortinet FortiClient EMS SQL Injection Vulnerability
Fortinet9.193.9%KEV2026-02-06
CVE-2024-43468
Microsoft Configuration Manager Remote Code Execution Vulnerability
Microsoft9.881.0%KEV2024-10-08
CVE-2025-57819
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
FreePBX10.086.3%KEV2025-08-28
CVE-2025-25257
Fortinet FortiWeb SQL Injection Vulnerability
Fortinet9.699.8%KEV2025-07-17
CVE-2025-25181
Advantive VeraCore SQL Injection Vulnerability
Advantive5.855.5%KEV2025-02-03
CVE-2024-9465
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
Palo Alto Networks9.299.6%KEV2024-10-09
CVE-2024-9379
Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
Ivanti6.543.8%KEV2024-10-08
CVE-2024-6670
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
Progress Software Corporation9.893.0%KEV2024-08-29
CVE-2023-48788
Fortinet FortiClient EMS SQL Injection Vulnerability
Fortinet9.398.4%KEV2024-03-12
CVE-2023-46748
BIG-IP Configuration utility authenticated SQL injection vulnerability
F58.84.5%KEV2023-10-26
CVE-2021-20028
SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability
SonicWall9.830.1%KEV2021-08-04
CVE-2019-7481
SonicWall SMA100 SQL Injection Vulnerability
SonicWall7.599.9%KEV2019-12-17
CVE-2021-20016
SonicWall SSLVPN SMA100 SQL Injection Vulnerability
SonicWall9.840.0%KEV2021-02-03
CVE-2026-20947
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft8.818.8%2026-01-13
CVE-2026-23696
Windmill < 1.603.3 File Ownership Handling SQLi RCE
Windmill Labs9.913.6%2026-04-07
CVE-2026-1207
Potential SQL injection via raster lookups on PostGIS
djangoproject5.412.8%2026-02-03

Frequently Asked Questions

What is CWE-89?→

CWE-89 is the MITRE entry for SQL injection, where input reaches an SQL command without neutralization and is interpreted as SQL.

What is the primary defense against SQL injection?→

MITRE recommends parameterization: prepared statements or parameterized queries that enforce separation between data and code, backed by least-privilege database accounts.

How many exploited vulnerabilities are classified as CWE-89?→

This database lists 20 CVE records mapped to CWE-89 by their CVE Numbering Authority. 17 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 5 to known ransomware campaigns. Examples include CVE-2026-9586, CVE-2026-72898, CVE-2026-9082.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.