← Back
CWE-89

20,650 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,650)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
13ds
1Push2rss 3ds
Apr 29, 2026
Jun 27, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the RSS feed from records extension 1.0.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Webempoweredchurch
1Wec Discussion
Apr 29, 2026
Jun 27, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the WEC Discussion Forum extension before 2.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Lina Wolf
1Seo Pack For Tt News
Apr 29, 2026
Jun 27, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the SEO Pack for tt_news extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typoheads
1Formhandler
Apr 29, 2026
Jun 27, 2013
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in the Formhandler extension before 1.4.1 for TYPO3 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via unspecified vectors.
1Christophe Balisky
1Meta Feedit
Apr 29, 2026
Jun 25, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the meta_feedit extension 0.1.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Bas Van Beek
1Multishop
Apr 29, 2026
Jun 25, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Multishop extension before 2.0.39 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Michael Staatz
1Sofortueberweisung2commerce
Apr 29, 2026
Jun 25, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the sofortueberweisung2commerce extension before 2.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Raphael Zschorsch
1Rzautocomplete
Apr 29, 2026
Jun 20, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the jQuery autocomplete for indexed_search (rzautocomplete) extension before 0.0.9 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Siemens
2Simatic Pcs7
Wincc
Apr 29, 2026
Jun 14, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, allows remote attackers to execute arbitrary SQL...Show more
SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.Show less
1Psychostats
1Psychostats
Apr 29, 2026
May 31, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in awards.php in PsychoStats 3.2.2b allows remote attackers to execute arbitrary SQL commands via the d parameter.
1Ibm
1Infosphere Optim Data Growth For Oracle E Business Suite
Apr 29, 2026
May 27, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote attackers to execute arbitrary SQL commands via unspecified vector...Show more
SQL injection vulnerability in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.Show less
1Wesley Destailleur
1Todoo Forum
Apr 29, 2026
May 13, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_post or (2) pg parameter.
1Whmcs
1Group Pay
Apr 29, 2026
May 13, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and earlier for WHMCS allows remote attackers to execute arbitrary SQL commands via the hash parameter.
1Virtualaccess
1Virtual Access Monitor
Apr 29, 2026
May 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Virtual Access Monitor 3.10.17 and earlier allow attackers to execute arbitrary SQL commands via unspecified vectors.
1Webdorado
1Spider Video Player
Apr 29, 2026
May 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter.
1Radiocms
1Radiocms
Apr 29, 2026
May 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in meneger.php in RadioCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the playlist_id parameter.
1Fabricio Zuardi
1Xspf Player Plugin
Apr 29, 2026
May 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in playlist.php in the Spiffy XSPF Player plugin 0.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the playlist_id parameter.
1Vanillaforums
1Vanilla
Apr 29, 2026
May 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter name in the Form/Email array to (1) entry/signin or (2) entry/passwordre...Show more
Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter name in the Form/Email array to (1) entry/signin or (2) entry/passwordrequest.Show less
1Bestpractical
1Request Tracker
Apr 29, 2026
May 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating...Show more
SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating "We were unable to replicate it, and the individual that reported it retracted their report," and "we had verified that the claimed exploit did not function according to the author's claims.Show less
1Simpilotgroup
1Pop Up News
Apr 29, 2026
May 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in popupnewsitem/ in the Pop Up News module 2.0 and possibly earlier for phpVMS allows remote attackers to execute arbitrary SQL commands via the itemid parameter. NOTE: this was originally r...Show more
SQL injection vulnerability in popupnewsitem/ in the Pop Up News module 2.0 and possibly earlier for phpVMS allows remote attackers to execute arbitrary SQL commands via the itemid parameter. NOTE: this was originally reported as a problem in phpVMS.Show less