← Back
CWE-89

20,631 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,631)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Componentslab
1Com Sqlreport
Apr 29, 2026
Feb 27, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the SQL Reports (com_sqlreport) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter to ajax/print.php. NOTE: some of these details...Show more
SQL injection vulnerability in the SQL Reports (com_sqlreport) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter to ajax/print.php. NOTE: some of these details are obtained from third party information.Show less
1Mhd Zaher Ghaibeh
1Arab Cart
Apr 29, 2026
Feb 26, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in showimg.php in Arab Cart 1.0.2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Mhproducts
1Ero Auktion
Apr 29, 2026
Feb 26, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Mhproducts
1Php Auktion Pro
Apr 29, 2026
Feb 26, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news.php in Php Auktion Pro allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Systemsoftware
1Auktionshaus Gelb
Apr 29, 2026
Feb 26, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news.php in Auktionshaus Gelb 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Systemsoftware
1Erotik Auktionshaus
Apr 29, 2026
Feb 26, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news.php in Erotik Auktionshaus allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Zenoss
1Zenoss
Apr 29, 2026
Feb 26, 2010
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticated users to execute arbitrary SQL commands via the (1) severity, (2) st...Show more
Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticated users to execute arbitrary SQL commands via the (1) severity, (2) state, (3) filter, (4) offset, and (5) count parameters.Show less
1Aspcodecms
1Aspcode Cms
Apr 29, 2026
Feb 25, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the newsid parameter when the sec parameter is...Show more
SQL injection vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the newsid parameter when the sec parameter is 26. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Netfortris
1Trixbox
Apr 29, 2026
Feb 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
1Newgensoft
1Omnidocs
Apr 29, 2026
Feb 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Dynamicsoft
1Wsc Cms
Apr 29, 2026
Feb 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in backoffice/login.asp in Dynamicsoft WSC CMS 2.2 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: some of these details are obtained from third pa...Show more
SQL injection vulnerability in backoffice/login.asp in Dynamicsoft WSC CMS 2.2 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: some of these details are obtained from third party information.Show less
1Cisco
1Security Agent
Apr 29, 2026
Feb 23, 2010
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via...Show more
SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.Show less
1Percha
1Com Perchagallery
Apr 29, 2026
Feb 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the PerchaGallery (com_perchagallery) component before 1.5b for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an editunidad action to index.php.
1Commodityrentals
1Trade Manager Script
Apr 29, 2026
Feb 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Iptechinside
1Com Jquarks
Apr 29, 2026
Feb 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the IP-Tech JQuarks (com_jquarks) Component 0.2.3, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: some...Show more
SQL injection vulnerability in the IP-Tech JQuarks (com_jquarks) Component 0.2.3, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: some of these details are obtained from third party information.Show less
1Jtl Software
1Jtl Shop
Apr 29, 2026
Feb 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands via the s parameter.
1Commodityrentals
1Video Games Rentals
Apr 29, 2026
Feb 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbitrary SQL commands via the pfid parameter in a catalog action.
1Katalog.hurricane
1Katalog Stron Hurricane
Apr 29, 2026
Feb 22, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the get parameter.
1Onnogroen
1Com Webeecomment
Apr 29, 2026
Feb 22, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a default action to...Show more
SQL injection vulnerability in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a default action to index2.php. NOTE: some of these details are obtained from third party information.Show less
1Copperleaf
1Photolog
Apr 29, 2026
Feb 22, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to execute arbitrary SQL commands via the postid parameter.