← Back
CWE-89

20,738 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,738)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cwjoomla
1Cw Tags
Jun 17, 2026
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.
1Codeigniter
1Codeigniter
Nov 21, 2024
Feb 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote attackers to execute arbitrary SQL commands via vectors involving the offset variable.
1Dotcms
1Dotcms
Nov 21, 2024
Feb 19, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_di...Show more
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.Show less
1Dotcms
1Dotcms
Nov 21, 2024
Feb 19, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy par...Show more
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.Show less
1Thethinkery
1Project Log
Jun 17, 2026
Feb 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter.
1Saxum2003
1Astro
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter.
1Squadmanagement Project
1Squadmanagement
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter.
1Saxum2003
1Saxum Picker
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter.
1Saxum2003
1Numerology
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter.
1Techjoomla
1Jticketing
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat parameter.
1Dthdevelopment
1Dt Register
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.
1Quanticalabs
1Timetable Responsive Schedule
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.
1Google Map Landkarten Project
1Google Map Landkarten
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action.
1Techjoomla
1Invitex
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action.
1Fastballproductions
1Fastball
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action.
1Joombooking
1Jb Bus
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter.
1Neojoomla
1Neorecruit
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI.
1Comdev
1Jomestate Pro
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action.
1Joomsky
1Js Autoz
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter.
1Realpin Project
1Realpin
Jun 17, 2026
Feb 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter.