CWE-89
20,738 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,738)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request. |
SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request. |
SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request. |
SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter. |
SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request. |
In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message. |
1Joomlacalendars 1Event Calendar Jun 17, 2026 Jan 30, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action. |
1Joomlacalendars 1Visual Calendar Jun 17, 2026 Jan 30, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action. |
MantisBT 2.10.0 allows local users to conduct SQL Injection attacks via the vendor/adodb/adodb-php/server.php sql parameter in a request to the 127.0.0.1 IP address. NOTE: the vendor disputes the significance of this rep...Show more |
FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order parameter. NOTE: the vendor disputes this issue because it is intentional that a user can "directly modif...Show more |
1Vastal 1I Tech Buddy Zone Facebook Clone Jun 17, 2026 Jan 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php category parameter. |
1Datacomponents 1Tsitebuilder Jun 17, 2026 Jan 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php. |
1Multilanguage Real Estate Mlm Script Project 1Multilanguage Real Estate Mlm Script Jun 17, 2026 Jan 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter. |
1Taskrabbit Clone Project 1Taskrabbit Clone Jun 17, 2026 Jan 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter. |
1Eihitech 1Professional Local Directory Script Jun 17, 2026 Jan 25, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryID or CategoryID parameter. |
Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and modules\Campaigns\utils.php, the default_currency_name parameter to modules\Config...Show more |
A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does not properly sanitize its inputs for SQL commands. |
1Emc 1Rsa Authentication Manager Nov 21, 2024 Jan 25, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulnerability. Authenticated malicious users could potentially exploit this vulnerability to read any une...Show more |
1Vehicle Sales Management System Project 1Vehicle Sales Management System Nov 21, 2024 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and login/sell.php script...Show more |
An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Multiple SQL injection vulnerabilities are present in the legacy .ASP pages, which could allow attackers to execute arbitrary SQL commands v...Show more |