cwe-89
Safeguard articles tagged "cwe-89" — guides, analysis, and best practices for software supply chain and application security.
38 articles
CVE-2026-21643: Fortinet FortiClient EMS SQL Injection Vulnerability
CVE-2026-21643 affects Fortinet FortiClient EMS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-13.
CVE-2026-42208: BerriAI LiteLLM SQL Injection Vulnerability
CVE-2026-42208 affects BerriAI LiteLLM and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-05-08.
CVE-2026-9082: Drupal Core SQL Injection Vulnerability
CVE-2026-9082 affects Drupal Core and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-05-22.
CVE-2026-60137: WordPress Core SQL Injection Vulnerability
CVE-2026-60137 affects WordPress Core and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-21.
CVE-2026-72898: Metabase SQL Injection Vulnerability
CVE-2026-72898 affects Metabase Metabase and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-11.
CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability
CVE-2026-9586 affects Sangoma Switchvox and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-09-02.
CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability
CVE-2026-76461 affects Cisco Secure Email Gateway and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-09-14.
MOVEit Transfer (CVE-2023-34362): A Mass Exploitation Data-Theft Campaign
A factual look at the 2023 Cl0p ransomware group campaign exploiting a SQL injection vulnerability in Progress Software MOVEit Transfer to steal data from hundreds of organizations.
SQL injection: a complete developer's guide
A developer's guide to SQL injection: how it works, why CWE-89 still ranks in MITRE's Top 25, real breaches, and how to detect and fix it.
Parameterized queries across languages: the real defense against SQL injection
SQL injection (CWE-89) still ranks #3 on the OWASP Top 10, but every major language has shipped a native, built-in fix for over a decade — most breaches happen anyway.
Preventing SQL injection in Node.js applications
CWE-89 is a 25-year-old bug class, but Node's template literals make it trivially easy to reintroduce in mysql2, pg, and even Sequelize's raw-query escape hatch.
SQL Injection in Go: Why database/sql Is Safe Until You Reach for Sprintf
database/sql gives Go parameterized queries for free — yet SQL injection still ships in Go services through dynamic query building, ORM escape hatches, and misused identifiers. Here's the line you can't cross.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.