← Back
CWE-89

20,640 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,640)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpkick
1Phpkick
Apr 29, 2026
Aug 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in statistics.php in PHPKick 0.8 allows remote attackers to execute arbitrary SQL commands via the gameday parameter in an overview action.
1Tycoon
1Baseball Script
Apr 29, 2026
Aug 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Tycoon Baseball Script 1.0.9 allows remote attackers to execute arbitrary SQL commands via the game_id parameter in a game_player action.
1Pligg
1Pligg Cms
Apr 29, 2026
Aug 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in groupadmin.php in Pligg before 1.1.1 allows remote attackers to execute arbitrary SQL commands via the role parameter, a different vulnerability than CVE-2010-2577.
1Pligg
1Pligg Cms
Apr 29, 2026
Aug 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Pligg before 1.1.1 allow remote attackers to execute arbitrary SQL commands via the title parameter to (1) storyrss.php or (2) story.php.
1Avscripts
1Av Arcade
Apr 29, 2026
Aug 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in AV Scripts AV Arcade 3 allows remote attackers to execute arbitrary SQL commands via the ava_code cookie to the "main page," related to index.php and the login task.
1Solucija
1Snews
Apr 29, 2026
Jul 30, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter.
1Openfreeway
1Freeway
Apr 29, 2026
Jul 30, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Freeway CMS 1.4.3.210 allows remote attackers to execute arbitrary SQL commands via the ecPath parameter.
1Silvercover
1Mylinksdump Plugin
Apr 29, 2026
Jul 30, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in myLDlinker.php in the myLinksDump Plugin 1.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the url parameter. NOTE: some of these details are obtained from th...Show more
SQL injection vulnerability in myLDlinker.php in the myLinksDump Plugin 1.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the url parameter. NOTE: some of these details are obtained from third party information.Show less
1Prasanna
1Com Youtube
Apr 29, 2026
Jul 30, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the YouTube (com_youtube) component 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_cate parameter to index.php.
1Ali Kenan
1Aky Blog
Apr 29, 2026
Jul 30, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.asp in AKY Blog allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Photoindochina
1Com Golfcourseguide
Apr 29, 2026
Jul 30, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Golf Course Guide (com_golfcourseguide) component 0.9.6.0 beta and 1 beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a golfcourses act...Show more
SQL injection vulnerability in the Golf Course Guide (com_golfcourseguide) component 0.9.6.0 beta and 1 beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a golfcourses action to index.php.Show less
1Joomlaxt
1Com Staticxt
Apr 29, 2026
Jul 30, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the StaticXT (com_staticxt) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
1Ajsquare
1Aj Hyip
Apr 29, 2026
Jul 30, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Ajsquare
1Aj Hyip
Apr 29, 2026
Jul 30, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Kayako
1Esupport
Apr 29, 2026
Jul 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action.
1Kayako
1Esupport
Apr 29, 2026
Jul 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a viewnews action.
1Alexred
1Com Oziogallery
Apr 29, 2026
Jul 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Ozio Gallery (com_oziogallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
1Toughtomato
1Com Ttvideo
Apr 29, 2026
Jul 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ttvideo.php in the TTVideo (com_ttvideo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a video action to index.php.
1Joomdle
1Com Joomdle
Apr 29, 2026
Jul 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Joomdle (com_joomdle) component 0.24 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the course_id parameter in a detail action to index.php.
1Huruhelpdesk
1Com Huruhelpdesk
Apr 29, 2026
Jul 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Huru Helpdesk (com_huruhelpdesk) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a detail action to index.php.