← Back
CWE-89

20,642 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,642)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Joachim Ruhs
1Event
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Event (event) extension before 0.3.7 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Allpcscript
1Allpc
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in product_info.php in ALLPC 2.5 allows remote attackers to execute arbitrary SQL commands via the products_id parameter.
1Joomla
1Com Camelcitydb2
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the CamelcityDB (com_camelcitydb2) component 2.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
1Joomla
1Com Elite Experts
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showExpertProfileDetailed action to...Show more
SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showExpertProfileDetailed action to index.php.Show less
1E Xoopport
1Samsara
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in location.php in the eCal module in E-Xoopport Samsara 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the lid parameter.
1Joomlamo
1Com Teams
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Teams (com_teams) component 1_1028_100809_1711 for Joomla! allows remote attackers to execute arbitrary SQL commands via the PlayerID parameter in a player save action to index.php.
1Wanewsletter
1Wanewsletter
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in WAnewsletter 2.1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Joomla
1Com Weblinks
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a categories action to index.php. NOTE: the provenanc...Show more
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a categories action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Robitbt
1Com Amblog
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the Amblog (com_amblog) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) articleid or (2) catid parameter to index.php.
1Webmaster Tips
1Com Slideshow
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
1Khader Abbeb
1Entrans
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in poll.php in Entrans 0.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sid parameter.
1Svcreation
1Get Tube
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in video.php in Get Tube 4.51 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Geeklog
1Geeklog
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in filemgmt/singlefile.php in Geeklog 1.3.8 allows remote attackers to execute arbitrary SQL commands via the lid parameter.
1Joostina Cms
1Com Ezautos
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Joostina (com_ezautos) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the firstCode parameter in a helpers action to index.php.
1Photoindochina
1Com Restaurantguide
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a country action to index.php.
1Timetrack
1Com Timetrack
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ct_id parameter in a timetrack action to index.php.
1Nuked Klan
1Partenaires Module
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in clic.php in the Partenaires module 1.5 for Nuked-Klan allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Virtuenetz
1Virtue Book Store
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in book/detail.php in Virtue Netz Virtue Book Store allows remote attackers to execute arbitrary SQL commands via the bid parameter.
1Allinta
1Allinta Cms
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Allinta CMS 22.07.2010 allow remote attackers to execute arbitrary SQL commands via the i parameter in an edit action to (1) contentAE.asp or (2) templatesAE.asp.
1Dmxready
1Polling Booth Manager
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in inc_pollingboothmanager.asp in DMXReady Polling Booth Manager allows remote attackers to execute arbitrary SQL commands via the QuestionID parameter in a results action.