Safeguard
Tag

cwe-89

Safeguard articles tagged "cwe-89" — guides, analysis, and best practices for software supply chain and application security.

38 articles

Vulnerability Analysis

CVE-2026-21643: Fortinet FortiClient EMS SQL Injection Vulnerability

CVE-2026-21643 affects Fortinet FortiClient EMS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-13.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-42208: BerriAI LiteLLM SQL Injection Vulnerability

CVE-2026-42208 affects BerriAI LiteLLM and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-05-08.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-9082: Drupal Core SQL Injection Vulnerability

CVE-2026-9082 affects Drupal Core and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-05-22.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-60137: WordPress Core SQL Injection Vulnerability

CVE-2026-60137 affects WordPress Core and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-21.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-72898: Metabase SQL Injection Vulnerability

CVE-2026-72898 affects Metabase Metabase and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-11.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability

CVE-2026-9586 affects Sangoma Switchvox and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-09-02.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability

CVE-2026-76461 affects Cisco Secure Email Gateway and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-09-14.

Sep 17, 20263 min read
Vulnerability Analysis

MOVEit Transfer (CVE-2023-34362): A Mass Exploitation Data-Theft Campaign

A factual look at the 2023 Cl0p ransomware group campaign exploiting a SQL injection vulnerability in Progress Software MOVEit Transfer to steal data from hundreds of organizations.

Sep 17, 20262 min read
Vulnerability Analysis

SQL injection: a complete developer's guide

A developer's guide to SQL injection: how it works, why CWE-89 still ranks in MITRE's Top 25, real breaches, and how to detect and fix it.

Aug 3, 20267 min read
Best Practices

Parameterized queries across languages: the real defense against SQL injection

SQL injection (CWE-89) still ranks #3 on the OWASP Top 10, but every major language has shipped a native, built-in fix for over a decade — most breaches happen anyway.

Jul 8, 20267 min read
Application Security

Preventing SQL injection in Node.js applications

CWE-89 is a 25-year-old bug class, but Node's template literals make it trivially easy to reintroduce in mysql2, pg, and even Sequelize's raw-query escape hatch.

Jul 7, 20267 min read
Security Guides

SQL Injection in Go: Why database/sql Is Safe Until You Reach for Sprintf

database/sql gives Go parameterized queries for free — yet SQL injection still ships in Go services through dynamic query building, ORM escape hatches, and misused identifiers. Here's the line you can't cross.

Jul 3, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.