← Back
CWE-89

20,643 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,643)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hypermethod
1Elearning Server
Apr 29, 2026
May 21, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news.php4 in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary SQL commands via the nid parameter.
1Johan Cwiklinski
1Galette
Apr 29, 2026
May 21, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in includes/picture.class.php in Galette 0.63, 0.63.1, 0.63.2, 0.63.3, and 0.64rc1 allows remote attackers to execute arbitrary SQL commands via the id_adh parameter to picture.php.
1Typo3
1Typo3
Apr 29, 2026
May 21, 2012
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in the list module in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via uns...Show more
SQL injection vulnerability in the list module in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via unspecified vectors.Show less
1Viscacha
1Viscacha
Apr 29, 2026
May 21, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in admin/bbcodes.php in Viscacha 0.8.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) bbcodeexample, (2) buttonimage, or (3) bbcodetag parameter.
1Ibm
1Rational Clearquest
Apr 29, 2026
May 14, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2 allows remote attackers to execute arbitrary SQL commands by leveragin...Show more
SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2 allows remote attackers to execute arbitrary SQL commands by leveraging an error in the user-database upgrade feature.Show less
1Php
1Php
Apr 29, 2026
May 11, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which a...Show more
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.Show less
1Hp
1Performance Insight
Apr 29, 2026
May 9, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Cisco
1Unified Meetingplace
Apr 29, 2026
May 2, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the web component in Cisco Unified MeetingPlace 7.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtx08939.
1Ryan Walberg
1Php Gift Registry
Apr 29, 2026
Apr 20, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in users.php in PHP Gift Registry 1.5.5 allows remote authenticated users to execute arbitrary SQL commands via the userid parameter in an edit action.
1Curl
2Curl
Libcurl
Apr 29, 2026
Apr 13, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrat...Show more
curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.Show less
1Ola Lasisi
1E Ticketing
Apr 29, 2026
Apr 11, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in loginscript.php in e-ticketing allows remote attackers to execute arbitrary SQL commands via the password parameter.
1Useasdf 4444
1Hotel Booking Portal
Apr 29, 2026
Apr 11, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL commands via the country parameter.
1F5
1Firepass
Apr 29, 2026
Apr 5, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL commands via the state parameter.
1Invensys
1Wonderware Information Server
Apr 29, 2026
Apr 2, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Rsa
1Envision
Apr 29, 2026
Mar 20, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
1Myjoblist
1Myjoblist
Apr 29, 2026
Mar 19, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in MyJobList 0.1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter in a profile action to index.php.
1Socialcms
1Socialcms
Apr 29, 2026
Mar 19, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search.php in SocialCMS 1.0.5 allows remote attackers to execute arbitrary SQL commands via the category parameter.
1Createvision
1Createvision Cms
Apr 29, 2026
Mar 19, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in artykul_print.php in CreateVision CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Symantec
1Altiris Wise Package Studio
Apr 29, 2026
Mar 17, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in Symantec Altiris WISE Package Studio before 8.0MR1 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Ibm
6Maximo Asset Management
Maximo Asset Management EssentialsMaximo Service Desk+3 more
Apr 29, 2026
Mar 13, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager...Show more
SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.Show less