← Back
CWE-89

20,631 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,631)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Insanevisions
1Onecms
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in OneCMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an elite action.
1Dev4u
1Dev4u Cms
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in go_target.php in dev4u CMS allows remote attackers to execute arbitrary SQL commands via the kontent_id parameter.
1Natychmiast Cms
1Natychmiast Cms
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Natychmiast CMS allow remote attackers to execute arbitrary SQL commands via the id_str parameter to (1) index.php and (2) a_index.php.
1Bfs.kilu
1Bigforum
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in profil.php in Bigforum 4.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Kiss Software
1Com Ksadvertiser
Apr 29, 2026
Mar 8, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Keep It Simple Stupid (KISS) Software Advertiser (com_ksadvertiser) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showcats a...Show more
SQL injection vulnerability in the Keep It Simple Stupid (KISS) Software Advertiser (com_ksadvertiser) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showcats action to index.php.Show less
1Hotbrackets
1Com Hotbrackets
Apr 29, 2026
Mar 8, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the HotBrackets Tournament Brackets (com_hotbrackets) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
1Mole Group
1Adult Portal Script
Apr 29, 2026
Mar 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in profile.php in Mole Group Adult Portal Script allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
1Beaussier
1Roomphplanning
Apr 29, 2026
Mar 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in RoomPHPlanning 1.6 allow remote attackers to execute arbitrary SQL commands via (1) the loginus parameter to Login.php or (2) the Old Password field to changepwd.php, and allow (...Show more
Multiple SQL injection vulnerabilities in RoomPHPlanning 1.6 allow remote attackers to execute arbitrary SQL commands via (1) the loginus parameter to Login.php or (2) the Old Password field to changepwd.php, and allow (3) remote authenticated administrators to execute arbitrary SQL commands via the id parameter to admin/userform.php.Show less
1Phpmember
1Webmember
Apr 29, 2026
Mar 5, 2010
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in form.php in WebMember 1.0 allows remote authenticated users to execute arbitrary SQL commands via the formID parameter.
1Jvideodirect
1Com Jvideodirect
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the jVideoDirect (com_jvideodirect) component 1.1 RC3b for Joomla! allows remote attackers to execute arbitrary SQL commands via the v parameter to index.php.
1Aleinbeen
1(nv2) Awards
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in (nv2) Awards 1.1.0, a modification for Invision Power Board, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.
1Joomservices
1Com Dms
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Ossolution Team Documents Seller (aka DMS) (com_dms) component 2.5.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a view_catego...Show more
SQL injection vulnerability in the Ossolution Team Documents Seller (aka DMS) (com_dms) component 2.5.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a view_category action to index.php.Show less
1Snowflake
1T3blog
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Harmistechnology
1Com Jeeventcalendar
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the JE Quiz (com_jequizmanagement) component 1.b01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the eid parameter in a question action to index.php.
1Harmistechnology
1Com Jeeventcalendar
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the JE Event Calendars (com_jeeventcalendar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an event action to index.php.
1Kuwaitphp
1Esmile
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in KuwaitPHP eSmile allows remote attackers to execute arbitrary SQL commands via the cid parameter in a show action.
1Commodityrentals
1Vacation Rental Software
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute arbitrary SQL commands via the rental_id parameter in a CalendarView action.
1Commodityrentals
1Cd Rental Software
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CommodityRentals CD Rental Software allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.
1Commodityrentals
1Books/ebooks Rentals Script
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a gamecatalog action.
1Softbizscripts
1Softbiz Jobs And Recruitment Script
Apr 29, 2026
Feb 27, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news_desc.php in Softbiz Jobs allows remote attackers to execute arbitrary SQL commands via the id parameter.