← Back
CWE-89

20,631 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,631)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gonafish
1Webstatcaffe
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in visitorduration.php in Gonafish WebStatCaffe allows remote attackers to execute arbitrary SQL commands via the nodayshow parameter. NOTE: the provenance of this information is unknown; the...Show more
SQL injection vulnerability in visitorduration.php in Gonafish WebStatCaffe allows remote attackers to execute arbitrary SQL commands via the nodayshow parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Tukanas
1Easyclassifieds Script
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Tukanas Classifieds (aka EasyClassifieds) Script 1.0 allows remote attackers to execute arbitrary SQL commands via the b parameter.
1Jan Bednarik
1Cooluri
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the CoolURI (cooluri) extension before 1.0.16 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2008-6686.
1Robert Heel
1Cwt Resetbepassword
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Reset backend password (cwt_resetbepassword) extension 1.20 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Dirk Maiwert
1Datamints Newsticker
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the datamints Newsticker (datamints_newsticker) extension before 0.7.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Maximo Cuadros
1Gb Fenewssubmit
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the [Gobernalia] Front End News Submitter (gb_fenewssubmit) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Ws Gallery
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Webesse Image Gallery (ws_gallery) extension 1.0.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Markus Barchfeld
1Pm Tour
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Tour Extension (pm_tour) extension before 0.0.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Liviu Mitrofan
1Myth Download
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Myth download (myth_download) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Alexandre Amaral
1Xoops Celepar
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) c...Show more
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to categoria.php.Show less
1Timeclock Software
1Employee Timeclock Software
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php.
1Radscripts
1Radnics
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in RadNICS Gold 5 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action.
1Radscripts
1Radlance
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action.
1Resalecode
1Classified Linktrader Script
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in addlink.php in Classified Linktrader Script allows remote attackers to execute arbitrary SQL commands via the slctCategories parameter.
1Resalecode
1Php Shopping Cart Selling Website Script
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Hypersilence
1Silentum Guestbook
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in silentum_guestbook.php in Silentum Guestbook 2.0.2 allows remote attackers to execute arbitrary SQL commands via the messageid parameter.
1Phpdirectorysource
1Phpdirectorysource
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to execute arbitrary SQL commands via the st parameter.
1Opencart
1Opencart
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.
1Media Products
1Bild Flirt Community
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Bild Flirt Community 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Preprojects
1Pre E Learning Portal
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL commands via the course_ID parameter.