← Back
CWE-89

20,650 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,650)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trivantis
1Coursemill Learning Management System
Apr 29, 2026
Sep 6, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admindocumentworker.jsp in Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to execute arbitrary SQL commands via the docID parameter.
3Cacti
DebianOpensuse
3Cacti
Debian LinuxOpensuse
Apr 29, 2026
Aug 29, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Myrephp
1Myre Business Directory
Apr 29, 2026
Aug 25, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in links.php in MYRE Business Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter.
1Myrephp
1Myre Vacation Rental
Apr 29, 2026
Aug 25, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in MYRE Vacation Rental Software allow remote attackers to execute arbitrary SQL commands via the (1) garage1 or (2) bathrooms1 parameter to vacation/1_mobile/search.php, or (3) uns...Show more
Multiple SQL injection vulnerabilities in MYRE Vacation Rental Software allow remote attackers to execute arbitrary SQL commands via the (1) garage1 or (2) bathrooms1 parameter to vacation/1_mobile/search.php, or (3) unspecified input to vacation/widgate/request_more_information.php.Show less
1Myrephp
1Myre Realty Manager
Apr 29, 2026
Aug 25, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in MYRE Realty Manager allow remote attackers to execute arbitrary SQL commands via the bathrooms1 parameter to (1) demo2/search.php or (2) search.php.
1Cacti
1Cacti
Apr 29, 2026
Aug 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in (1) api_poller.php and (2) utility.php in Cacti before 0.8.8b allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Heiko Sudar
1Slideshare
Apr 29, 2026
Aug 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Slideshare extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Jan Bednarik
1Cooluri
Apr 29, 2026
Aug 20, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the CoolURI extension before 1.0.30 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Alienvault
1Open Source Security Information Management
Apr 29, 2026
Aug 20, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to fore...Show more
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2) tcp_flags[] or (3) tcp_port[0][4] parameter to forensics/base_stat_alerts.php; the (4) ip_addr[1][8] or (5) port_type parameter to forensics/base_stat_ports.php; or the (6) sortby or (7) rvalue parameter in a search action to vulnmeter/index.php.Show less
1Benjamin Arnaudetr
1Ginkgocms
Apr 29, 2026
Aug 20, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Ginkgo CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the rang parameter to index.php.
1Vastal
1Phpvid
Apr 29, 2026
Aug 19, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL commands via the "n" parameter to (1) browse_videos.php or (2) members.php. NOTE: the cat parameter is...Show more
Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL commands via the "n" parameter to (1) browse_videos.php or (2) members.php. NOTE: the cat parameter is already covered by CVE-2008-4157.Show less
1Mauro Lorenzutti
1Wfqbe
Apr 29, 2026
Aug 16, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the DB Integration (wfqbe) extension before 2.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Die Netzmacher
1Browser
Apr 29, 2026
Aug 16, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Browser - TYPO3 without PHP (browser) extension before 4.5.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Joachim Ruhs
1Locator
Apr 29, 2026
Aug 16, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Kennziffer
1Ke Search
Apr 29, 2026
Aug 16, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Faceted Search (ke_search) extension before 1.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Phpfox
1Phpfox
Apr 29, 2026
Aug 14, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in PHPFox before 3.6.0 (build6) allows remote attackers to execute arbitrary SQL commands via the search[sort_by] parameter to user/browse/view_/.
1Phpfox
1Phpfox
Apr 29, 2026
Aug 14, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands via the search[gender] parameter to user/browse/view_/.
1Bigtreecms
1Bigtree Cms
Apr 29, 2026
Aug 14, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to index.php.
1Cotonti
1Cotonti Siena
Apr 29, 2026
Aug 9, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary SQL commands via the "c" parameter to index.php.
1Open Emr
1Openemr
Apr 29, 2026
Aug 9, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in OpenEMR 4.1.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) start or (2) end parameter to interface/reports/custom_report_range.php, or the (3) f...Show more
Multiple SQL injection vulnerabilities in OpenEMR 4.1.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) start or (2) end parameter to interface/reports/custom_report_range.php, or the (3) form_newid parameter to custom/chart_tracker.php.Show less