← Back
CWE-89

20,633 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,633)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zentracking
1Zen Time Tracking
Apr 29, 2026
Mar 23, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to...Show more
Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to (a) userlogin.php and (b) managerlogin.php. NOTE: some of these details are obtained from third party information.Show less
1Alexandre Dubus
1Audistat
Apr 29, 2026
Mar 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) month parameters. NOTE: the provenance of this information is unknown...Show more
Multiple SQL injection vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) month parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Alexandre Dubus
1Audistat
Apr 29, 2026
Mar 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via the mday parameter.
1Uiga
1Business Portal
Apr 29, 2026
Mar 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Uiga Business Portal allow remote attackers to execute arbitrary SQL commands via the (1) noentryid parameter to blog/index.php and the (2) p parameter to index2.php.
1Masa2el
1Music City
Apr 29, 2026
Mar 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in MASA2EL Music City 1.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a singer action.
1Ryan Marshall
1Rostermain
Apr 29, 2026
Mar 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in index.php in Rostermain 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) userid (username) and (2) password parameters.
1Design Cars
1Com Productbook
Apr 29, 2026
Mar 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Productbook (com_productbook) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: some of...Show more
SQL injection vulnerability in the Productbook (com_productbook) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: some of these details are obtained from third party information.Show less
1Manageengine
1Oputils
Apr 29, 2026
Mar 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpPort parameter.
1Dietmar Schffer
1Travelmate
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Meet Travelmates (travelmate) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Mathon Nicolas
1Tmsw Cleandb
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the CleanDB - DBAL (tmsw_cleandb) extension 2.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Chris Wederka
1Tgm Newsletter
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the TGM-Newsletter (tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Sk Typo3
1Sk Simplegallery
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Simple Gallery (sk_simplegallery) extension 0.0.9 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Jochen Rau
1Sk Bookreview
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Book Reviews (sk_bookreview) extension 0.0.12 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Laurent Foulloy
1Sav Filter Months
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the SAV Filter Months (sav_filter_months) extension before 1.0.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Laurent Foulloy
1Sav Filter Selectors
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the SAV Filter Selectors (sav_filter_selectors) extension before 1.0.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Laurent Foulloy
1Sav Filter Abc
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the SAV Filter Alphabetic (sav_filter_abc) extension before 1.0.9 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Fr.simon Rundell
1Pd Diocesedatabase
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Diocese of Portsmouth Database (pd_diocesedatabase) extension before 0.7.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Mathias Schreiber
1Nf Cleandb
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the CleanDB (nf_cleandb) extension 1.0.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Matthias Kall
1Mk Wastebasket
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the MK Wastebasket (mk_wastebasket) extension 2.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Joachim Ruhs
1Educator
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Educator extension 0.1.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.