← Back
CWE-89

20,642 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,642)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gbu Grafici
1Com Gbufacebook
Apr 29, 2026
Nov 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the face_id parameter in a show_face action to index.php.
1Almnzm
1Almnzm
Apr 29, 2026
Nov 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Almnzm 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Php Shop System
1Com Xobbix
Apr 29, 2026
Nov 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a prod_desc action to index.php.
1Zabbix
1Zabbix
Apr 29, 2026
Nov 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in events.php in Zabbix 1.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the nav_time parameter.
1V Eva
1Press Release Script
Apr 29, 2026
Nov 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Sir
1Gnuboard
Apr 29, 2026
Nov 4, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.
1Hiroyuki Oyama
1Dbd\
Apr 29, 2026
Nov 4, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in DBD::mysqlPP 0.04 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Kanich
1Com Searchlog
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remote authenticated users, with Public Back-end privileges, to execute arbitrary SQL commands via the se...Show more
SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remote authenticated users, with Public Back-end privileges, to execute arbitrary SQL commands via the search parameter in a log action to administrator/index.php. NOTE: some of these details are obtained from third party information.Show less
1Blueconstantmedia
1Com Djartgallery
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the cid[] parameter in an editItem action to adminis...Show more
SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the cid[] parameter in an editItem action to administrator/index.php.Show less
1John Bradshaw
1Np Gallery Plugin
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action.
1Scriptsfeed
1Recipes Listing Portal
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some o...Show more
SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.Show less
1Michau Enterprises
1Sensesites Commonsense Cms
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
1Iscripts
1Eswap
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.
1Iscripts
1Easybiller
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter.
1Fusebox
1Fusebox
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL commands via the CatDisplay parameter.
1Tamlyncreative
1Com Bfquiztrial
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a bfquiztrial action to index.php.
1Codefabrik
1Ecomat Cms
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the show parameter in a web action.
1Harmistechnology
1Com Jejob
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php.
1Sfiab
1Science Fair In A Box
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from...Show more
SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from third party information.Show less
1Cutesite
1Cutesite Cms
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via the user_id parameter. NOTE: some of thes...Show more
SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via the user_id parameter. NOTE: some of these details are obtained from third party information.Show less