← Back
CWE-89

20,631 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,631)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Joomla
1Com Dhforum
Apr 23, 2026
Jan 6, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the DhForum (com_dhforum) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a grouplist action to index.php.
1Xoops
1Xoops Dictionary
Apr 23, 2026
Jan 6, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Maxdev
1Mdforum
Apr 23, 2026
Jan 6, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the MDForum module 2.x through 2.07 for MAXdev MDPro allows remote attackers to execute arbitrary SQL commands via the c parameter to index.php.
1Cmstactics
1Com Beeheard
Apr 23, 2026
Jan 6, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the BeeHeard (com_beeheard) component 1.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a suggestions action to index.php.
1I Escorts
1I Escorts Directory Script
Apr 23, 2026
Jan 6, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in country_escorts.php in I-Escorts Directory Script allows remote attackers to execute arbitrary SQL commands via the country_id parameter.
1Phpshop
1Phpshop
Apr 23, 2026
Jan 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL commands via the (1) module_id parameter in an admin/function_list action, the (2) vendor_id parameter...Show more
Multiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL commands via the (1) module_id parameter in an admin/function_list action, the (2) vendor_id parameter in a vendor/vendor_form action, the (3) module_id parameter in an admin/module_form action, the (4) user_id parameter in an admin/user_form action, the (5) vendor_category_id parameter in a vendor/vendor_category_form action, the (6) user_id parameter in a store/user_form action, the (7) payment_method_id parameter in a store/payment_method_form action, the (8) tax_rate_id parameter in a tax/tax_form action, or the (9) category parameter in a shop/browse action. NOTE: the product_id vector is already covered by CVE-2008-0681.Show less
1Elkagroup
1Image Gallery
Apr 23, 2026
Jan 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/.
1Zenphoto
1Zenphoto
Apr 23, 2026
Jan 4, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote attackers to execute arbitrary SQL commands via the title parameter in a news action. NOTE: the provenance of this information is unknown; the det...Show more
SQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote attackers to execute arbitrary SQL commands via the title parameter in a news action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Zenphoto
1Zenphoto
Apr 23, 2026
Jan 4, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute arbitrary SQL commands via the category parameter, related to a URI under news/category/.
1Worms League
1Webleague
Apr 23, 2026
Jan 4, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
1Worms League
1Webleague
Apr 23, 2026
Jan 4, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in profile.php in WebLeague 2.2.0 allows remote attackers to execute arbitrary SQL commands via the name parameter.
1Intesync
1Miniweb
Apr 23, 2026
Jan 4, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a results action to index.php.
1Kunena
1Kunena Forum
Apr 23, 2026
Jan 4, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the func parameter to index.php.
1Bpowerhouse
1Mini Cms
Apr 23, 2026
Jan 4, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in page.php in Mini CMS 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Zabbix
1Zabbix
Apr 23, 2026
Dec 31, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to execute arbitrary SQL commands via a crafted request, possibly related...Show more
SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to execute arbitrary SQL commands via a crafted request, possibly related to the send_history_last_id function in zabbix_server/trapper/nodehistory.c.Show less
1Xstate
1Real Estate
Apr 23, 2026
Dec 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in page.html in Xstate Real Estate 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
1Joomlub
1Com Joomlub
Apr 23, 2026
Dec 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Joomlub (com_joomlub) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an auction edit action to index.php.
1Mikedeboer
1Com Zoom
Apr 23, 2026
Dec 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Mike de Boer zoom (com_zoom) component 2.0 for Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
1Dvbbs
1Dvbbs
Apr 23, 2026
Dec 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in boardrule.php in DVBBS 2.0 allows remote attackers to execute arbitrary SQL commands via the groupboardid parameter.
1Greendesktiny
1Green Desktiny
Apr 23, 2026
Dec 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news_detail.php in Green Desktiny 2.3.1, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the id parameter.