← Back
CWE-89

20,631 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,631)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Indianpulses
1Com Gameserver
Apr 29, 2026
Jan 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the indianpulse Game Server (com_gameserver) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the grp parameter in a gameserver action to index.php.
1Fabricadigital
1Publique!
Apr 29, 2026
Jan 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cgi/cgilua.exe/sys/start.htm in Publique! 2.3 allows remote attackers to execute arbitrary SQL commands via the sid parameter.
1Cisco
1Unified Meetingplace
Apr 29, 2026
Jan 28, 2010
N/A· v4
N/A· v3
9.0 HIGH· v2
Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspec...Show more
Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691.Show less
1Phpmyspace
1Phpmyspace
Apr 29, 2026
Jan 22, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in modules/arcade/index.php in PHP MySpace Gold Edition 8.0 and 8.10 allows remote attackers to execute arbitrary SQL commands via the gid parameter in a show_stats action. NOTE: the provenan...Show more
SQL injection vulnerability in modules/arcade/index.php in PHP MySpace Gold Edition 8.0 and 8.10 allows remote attackers to execute arbitrary SQL commands via the gid parameter in a show_stats action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Phpmyspace
1Phpmyspace
Apr 29, 2026
Jan 21, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in modules/arcade/index.php in PHP MySpace Gold Edition 8.0 and 8.10 allows remote attackers to execute arbitrary SQL commands via the gid parameter in a play_game action. NOTE: some of these...Show more
SQL injection vulnerability in modules/arcade/index.php in PHP MySpace Gold Edition 8.0 and 8.10 allows remote attackers to execute arbitrary SQL commands via the gid parameter in a play_game action. NOTE: some of these details are obtained from third party information.Show less
1Jce Tech
1Php Calendars Script
Apr 29, 2026
Jan 21, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this information...Show more
SQL injection vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Joomla
1Com Libros
Apr 29, 2026
Jan 21, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.
1Hong Chuyen
1Com Articlemanager
Apr 29, 2026
Jan 21, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Articlemanager (com_articlemanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the artid parameter in a display action to index.php.
1Templateplaza
1Com Tpdugg
Apr 23, 2026
Jan 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tags action to index.php.
1Tamlyncreative
1Com Bfsurvey Profree
Apr 23, 2026
Jan 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows...Show more
SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the table parameter in an updateOnePage action to index.php.Show less
1Nicecoder
1Idesk
Apr 23, 2026
Jan 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2005-3843.
1Patching
1Jianghu Inn
Apr 23, 2026
Jan 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to forummission.php.
1Joomloc
1Com Joomloc
Apr 23, 2026
Jan 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Joomloc (com_joomloc) component 1.0 for Joomla allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.
1Lucygames
1Com Lucygames
Apr 23, 2026
Jan 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Lucy Games (com_lucygames) component 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a game action to index.php. NOTE: some of t...Show more
SQL injection vulnerability in the Lucy Games (com_lucygames) component 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a game action to index.php. NOTE: some of these details are obtained from third party information.Show less
1Tourismscripts
1Bus Script
Apr 23, 2026
Jan 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Tourism Script Bus Script allow remote attackers to execute arbitrary SQL commands via the sitetext_id parameter to (1) aboutus.php and (2) faq.php.
1Tourismscripts
1Tourism Script Accomodation Hotel Booking Portal Script
Apr 23, 2026
Jan 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attackers to execute arbitrary SQL commands via the hotel_id parameter to (1) hotel.php, (2) details.php, (3...Show more
Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attackers to execute arbitrary SQL commands via the hotel_id parameter to (1) hotel.php, (2) details.php, (3) roomtypes.php, (4) photos.php, (5) map.php, (6) weather.php, (7) reviews.php, and (8) book.php.Show less
1Myrephp
1Myre Holiday Rental Manager
Apr 23, 2026
Jan 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in review.php in MYRE Holiday Rental Manager allows remote attackers to execute arbitrary SQL commands via the link_id parameter in a show_review action.
1Typo3
1Zak Store Management
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the zak_store_management extension 1.0.0 and earlier TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Pb Clanlist
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Clan Users List (pb_clanlist) extension 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Job Reports
Apr 23, 2026
Jan 15, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Reports for Job (job_reports) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.