Cwe-89 - SQL Injection - Cwe

Threat entity extracted from intelligence sources

Frequency
165
occurrences
First Seen
April 16, 2026
Last Seen
July 19, 2026

Cwe-89 - SQL Injection is a cwe tracked across 50 threat clusters and 165 intelligence report mentions on ThreatCluster. First observed April 16, 2026; most recent activity July 19, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • "Wp2shell: Critical WordPress Gap Allows Code Insertion via API — www.heise.de · July 19, 2026
  • Cloudflare Has Urgently Deployed Cloud-Based WAF Rules to Block Attacks Targeting the High-Risk Remote Code Execution Vulnerability in WordPress. — unsafe.sh · July 18, 2026
  • Cloudflare WAF Protects WordPress Applications From Two High — Ground.News · July 18, 2026
  • "WP2Shell" Critical WordPress RCE Chain (CVE-2026-63030 & CVE-2026-60137) Beazley Security Labs Advisories and Articles / 6h Beazley Security strongly recommends organizations apply available patches immediately, or deploy mitigations such as WAF rules. WordPress made patches available before public disclosure, and Cloudflare simultaneously released Web Application Firewall (WAF) protections for sites behind its service. — labs.beazley.security · July 18, 2026
  • Anthropic's Eugene Yan: AI Can Find 20× More Software Bugs. The Real Crisis Is What ... — Finance.Biggo · July 18, 2026
  • Critical wp2shell vulnerability enables unauthenticated RCE in WordPress core — Feeds.4Sysops · July 18, 2026
  • Using LLMs to Secure Source Code — Eugene Yan, Anthropic|AI Engineer — Finance.Biggo · July 18, 2026
  • Declassified Intelligence and Electoral Vulnerability: A Rig — Weddings.Lavenderhotels · July 18, 2026

CVSS v3.1 Breakdown