← Back
CWE-89

20,642 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,642)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Micronetsoft
1Rental Property Website
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detail.asp in Micronetsoft Rental Property Management Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ad_ID parameter.
1Micronetsoft
1Rv Dealer Website
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detail.asp in Micronetsoft RV Dealer Website 1.0 allows remote attackers to execute arbitrary SQL commands via the vehicletypeID parameter.
1A Blog
1A Blog
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in sources/search.php in A-Blog 2.0 allows remote attackers to execute arbitrary SQL commands via the words parameter.
1Coldgen
1Coldusergroup
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in index.cfm in ColdGen ColdUserGroup 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) ArticleID or (2) LibraryID parameter.
1Coldgen
1Coldbookmarks
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL commands via the BookmarkID parameter in an EditBookmark action.
1Discuz
1Ucenter Home
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parameter in a view action.
1Sellatsite
1Php Classifieds Ads
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL commands via the sid parameter.
1Coldgen
1Coldcalendar
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.cfm in ColdGen ColdCalendar 2.06 allows remote attackers to execute arbitrary SQL commands via the EventID parameter in a ViewEventDetails action.
1Virtuenetz
1Virtue Shopping Mall
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detail.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the prodid parameter.
1Zenphoto
1Zenphoto
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a parameter. NOTE: some of these details are obtained from third party...Show more
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a parameter. NOTE: some of these details are obtained from third party information.Show less
1Softbizscripts
1Article Directory Script
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in article_details.php in Softbiz Article Directory Script allows remote attackers to execute arbitrary SQL commands via the sbiz_id parameter.
1Simon Philips
1Com Aardvertiser
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter in a view action to index.php....Show more
SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter in a view action to index.php. NOTE: some of these details are obtained from third party information.Show less
1Cubecart
1Cubecart
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.
1Joomla Clantools
1Clantools
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.
1Webmanager Pro
1Cms Webmanager Pro
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in c.php in CMS WebManager-Pro before 8.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Gantry Framework
1Com Gantry
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Gantry (com_gantry) component 3.0.10 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter to index.php.
1Bluecms Project
1Bluecms
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in comment.php in BlueCMS 1.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header in a send action.
1Chillycms
1Chillycms
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information...Show more
SQL injection vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information.Show less
1Andreas Kiefer
1Ke Yac
Apr 29, 2026
Oct 7, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Yet Another Calendar (ke_yac) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Marco Hezel
1Hm Tinymarket
Apr 29, 2026
Oct 7, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Tiny Market (hm_tinymarket) extension 0.5.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.