← Back
CWE-89

20,642 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,642)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Raphael Zschorsch
1Commentsbe
Apr 29, 2026
Oct 7, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Commenting system Backend Module (commentsbe) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Mblogger Project
1Mblogger
Apr 29, 2026
Oct 7, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in viewpost.php in mBlogger 1.0.04 allows remote attackers to execute arbitrary SQL commands via the postID parameter.
1Pilotcart
1Pilot Cart
Apr 29, 2026
Oct 7, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in newsroom.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the specific parameter.
1Bloofox
1Bloofoxcms
Apr 29, 2026
Oct 7, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.
1Drbenhur
1Dbhcms
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in DBHcms 1.1.4 allows remote attackers to execute arbitrary SQL commands via the editmenu parameter.
1Chipmunk Scripts
1Chipmunk Board
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands via the forumID parameter.
1Harmistechnology
1Com Jeguestbook
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the d_itemid parameter in an item_detail action to index.php.
1Danieljamesscott
1Com Clubmanager
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cm_id parameter in an equip presenta action to index.php.
1Harmistechnology
1Com Jedirectory
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the JExtensions JE Directory (com_jedirectory) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php.
1Webspell
1Webspell
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.
1Galaxyscriptz
1Myphpauction
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Webasyst
1Shop Script
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in WebAsyst Shop-Script allows remote attackers to execute arbitrary SQL commands via the blog_id parameter in a news action.
1Curtiss Grymala
1Cag Cms
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in click.php in CAG CMS 0.2 Beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
1Aspindir
1Xweblog
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.
1Aspindir
1Xweblog
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter.
1Zuitu
1Zuitu
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in ajax/coupon.php in Zuitu 1.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a consume action.
1Chillcreations
1Com Ccinvoices
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to index.php.
1Netshinesoftware
1Com Netinvoice
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in netinvoice.php in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving "knowledge of ... th...Show more
SQL injection vulnerability in netinvoice.php in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving "knowledge of ... the contents of an encrypted file."Show less
1Sclek
1Jsite
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/login.php in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are o...Show more
SQL injection vulnerability in admin/login.php in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Symantec
1Im Manager
Apr 29, 2026
Oct 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the management console in Symantec IM Manager before 8.4.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.