← Back
CWE-89

20,638 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,638)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Winterwebs
1Ezwebitor
Apr 29, 2026
Jul 12, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL commands via the (1) txtUserId (Username) and (2) txtPassword (Password) parameters. NOTE: some of these...Show more
Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL commands via the (1) txtUserId (Username) and (2) txtPassword (Password) parameters. NOTE: some of these details are obtained from third party information.Show less
1Creasito
1Creasito E Commerce Content Manager
Apr 29, 2026
Jul 12, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the...Show more
Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) admin/checkuser.php and (2) checkuser.php.Show less
1Joomla
2Com Weblinks
Joomla
Apr 29, 2026
Jul 8, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
1Guillermo Vargas
1Com Xmap
Apr 29, 2026
Jul 8, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in xmap (com_xmap) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
1Alanzard
1Tsoka\
Apr 29, 2026
Jul 8, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an articolo action.
1Devana
1Devana
Apr 29, 2026
Jul 8, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Ez
1Ez Publish
Apr 29, 2026
Jul 8, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) SectionID and (2) SearchTimestamp parameters to the search feature and the (3)...Show more
Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) SectionID and (2) SearchTimestamp parameters to the search feature and the (3) SearchContentClassAttributeID parameter to the advancedsearch feature.Show less
1Brotherscripts
1Recipe Website
Apr 29, 2026
Jul 8, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in recipedetail.php in BrotherScripts Recipe Website allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Mahara
1Mahara
Apr 29, 2026
Jul 6, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Mahara 1.1.x before 1.1.9 and 1.2.x before 1.2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Tornadostore
1Tornadostore
Apr 29, 2026
Jul 6, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_couri...Show more
Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.Show less
1Iscripts
1Easysnaps
Apr 29, 2026
Jul 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) values parameter to tags_details.php, or (3...Show more
Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) values parameter to tags_details.php, or (3) begin parameter to greetings.php.Show less
1Internetdm
1Bed And Breakfast
Apr 29, 2026
Jul 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in pages.php in Internet DM Specialist Bed and Breakfast allows remote attackers to execute arbitrary SQL commands via the pp_id parameter.
1Joomanager
1Joomanager
Apr 29, 2026
Jul 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
1Paul Mcenery
1Php Bible Search
Apr 29, 2026
Jul 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in bible.php in PHP Bible Search, probably 0.99, allows remote attackers to execute arbitrary SQL commands via the chapter parameter.
1Grafik Power
1Grafik Cms
Apr 29, 2026
Jul 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/admin.php in Grafik CMS 1.1.2, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit_page action.
1I Netsolution
1Job Search Engine Script
Apr 29, 2026
Jul 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in show_search_result.php in i-netsolution Job Search Engine allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
12daybiz
1Job Site Script
Apr 29, 2026
Jul 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in 2daybiz Job Site Script allow remote attackers to execute arbitrary SQL commands via the (1) jid parameter to view_current_job.php, (2) job_iid parameter to show_search_more.php,...Show more
Multiple SQL injection vulnerabilities in 2daybiz Job Site Script allow remote attackers to execute arbitrary SQL commands via the (1) jid parameter to view_current_job.php, (2) job_iid parameter to show_search_more.php, and (3) left_cat parameter to show_search_result.php.Show less
12daybiz
1Job Search Engine Script
Apr 29, 2026
Jul 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
1Ordasoft
1Com Booklibrary
Apr 29, 2026
Jul 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the BookLibrary Basic (com_booklibrary) component 1.5.3 before 1.5.3_2010_06_20 for Joomla! allow remote attackers to execute arbitrary SQL commands via the bid[] parameter in a...Show more
Multiple SQL injection vulnerabilities in the BookLibrary Basic (com_booklibrary) component 1.5.3 before 1.5.3_2010_06_20 for Joomla! allow remote attackers to execute arbitrary SQL commands via the bid[] parameter in a (1) lend_request or (2) save_lend_request action to index.php, the id parameter in a (3) mdownload or (4) downitsf action to index.php, or (5) the searchtext parameter in a search action to index.php.Show less
1Taskfreak
1Taskfreak
Apr 29, 2026
Jun 30, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in include/classes/tzn_user.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to execute arbitrary SQL commands via the password parameter to login.php.