← Back
CWE-89

20,642 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,642)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Esoftpro
1Online Photo Pro
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in esoftpro Online Photo Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the section parameter.
1Esoftpro
1Online Guestbook Pro
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ogp_show.php in esoftpro Online Guestbook Pro 5.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.
1Neojoomla
1Com Neorecruit
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the NeoRecruit (com_neorecruit) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in an offer_view action to index.php, a differ...Show more
SQL injection vulnerability in the NeoRecruit (com_neorecruit) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in an offer_view action to index.php, a different vector than CVE-2007-4506.Show less
1Instantphp
1Jobs Pro
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Jobs Pro component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the detailed_results parameter to search_jobs.html.
1Kay Messerschmidt
1Com Eventcal
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the eventcal (com_eventcal) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
1Paymentsplus
1Payments Plus
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Payments Plus component 2.1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the type parameter to add.html.
1Ninjaforge
1Ninjamonials
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the NinjaMonials (com_ninjamonials) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a display action to index.php.
1B Elektro
1Com Addressbook
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Front-edit Address Book (com_addressbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a contact action to index.php.
1Farsi Cms
1Ziggurat Farsi Cms
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in main.asp in Ziggurat Farsi CMS allows remote attackers to execute arbitrary SQL commands via the grp parameter.
1Kmsoft
1Guestbook
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.asp in KMSoft Guestbook (aka GBook) allows remote attackers to execute arbitrary SQL commands via the p parameter.
1Cafuego
1Simple Document Management System
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute arbitrary SQL commands via the doc_id parameter.
1Mykazaam
1Notes Management System
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to execute arbitrary SQL commands via vectors involving the "Enter Reference Number Below" text box.
1Iscripts
1Cybermatch
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Mykazaam
1Address & Contact Organizer
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in address_book/contacts.php in My Kazaam Address & Contact Organizer allows remote attackers to execute arbitrary SQL commands via the var1 parameter.
1Yourfreeworld
1Banner Management
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party in...Show more
SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.Show less
1Iscripts
1Reservelogic
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
1Nicholas Berry
1Candid
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in image/view.php in CANDID allows remote attackers to execute arbitrary SQL commands via the image_id parameter.
1Miniwork
1Com Canteen
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the mealid parameter to index.php.
1Techjoomla
1Com Socialads
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Techjoomla SocialAds For JomSocial (com_socialads) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the ads description field in a showad action to in...Show more
SQL injection vulnerability in the Techjoomla SocialAds For JomSocial (com_socialads) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the ads description field in a showad action to index.php.Show less
1Brotherscripts
1Auto Dealer
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in info.php in BrotherScripts (BS) and ScriptsFeed Auto Dealer allows remote attackers to execute arbitrary SQL commands via the id parameter.