← Back
CWE-89

20,620 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,620)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Elvinbts
1Elvinbts
Apr 23, 2026
Jun 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/login.ei, reachable thr...Show more
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/login.ei, reachable through login.php; and the (3) id parameter to (b) show_bug.php and (c) show_activity.php. NOTE: it was later reported that vector 3c also affects 1.2.2.Show less
1Paolo Palmonari
1Photoracer Plugin For Wordpress
Apr 23, 2026
Jun 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Tekbase
1Tekbase All In One
Apr 23, 2026
Jun 18, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in TekBase All-in-One 3.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) ids parameter to admin.php, the (2) y parameter to members.php, and other un...Show more
Multiple SQL injection vulnerabilities in TekBase All-in-One 3.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) ids parameter to admin.php, the (2) y parameter to members.php, and other unspecified vectors. NOTE: vector 1 requires administrative access.Show less
1Fretsweb Project
1Fretsweb
Apr 23, 2026
Jun 18, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to player.php and the (2) hash parameter to song.php.
1Projektseminar Proservice Wwu
1Virtual Civil Services
Apr 23, 2026
Jun 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Virtual Civil Services (civserv) extension 4.3.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Kasper Skrhj
1References Database
Apr 23, 2026
Jun 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the References database (t3references) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Steve Grundell
1Frontend Mp3 Player
Apr 23, 2026
Jun 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Frontend MP3 Player (fe_mp3player) 0.2.3 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Com Jumi
1Com Jumi
Apr 23, 2026
Jun 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote attackers to execute arbitrary SQL commands via the fileid parameter to index.php.
1Ijoomla
1Com Rssfeeder
Apr 23, 2026
Jun 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in an xml action to index.php.
1Micheal Glazer
1Phportal
Apr 23, 2026
Jun 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Zokisoft
1Zoki Catalog
Apr 23, 2026
Jun 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in system/application/controllers/catalog.php in Zoki Soft Zoki Catalog (aka Smart Catalog) allows remote attackers to execute arbitrary SQL commands via the search_text parameter. NOTE: some...Show more
SQL injection vulnerability in system/application/controllers/catalog.php in Zoki Soft Zoki Catalog (aka Smart Catalog) allows remote attackers to execute arbitrary SQL commands via the search_text parameter. NOTE: some of these details are obtained from third party information.Show less
1David Degner
1Phpcollegeexchange
Apr 23, 2026
Jun 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute arbitrary SQL commands via the itemnr parameter.
1Creative Web Solutions
1Multi Level Cms
Apr 23, 2026
Jun 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in insidepage.php in Creative Web Solutions Multi-Level CMS 1.21 allows remote attackers to execute arbitrary SQL commands via the catid parameter. NOTE: some of these details are obtained fr...Show more
SQL injection vulnerability in insidepage.php in Creative Web Solutions Multi-Level CMS 1.21 allows remote attackers to execute arbitrary SQL commands via the catid parameter. NOTE: some of these details are obtained from third party information.Show less
1Geekbill
1Open Biller
Apr 23, 2026
Jun 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Open Biller 0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
1Ricardo Alexandre De Oliveira Staudt
1Yogurt
Apr 23, 2026
Jun 12, 2009
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authenticated users to execute arbitrary SQL commands via the original parameter.
1Shop Script
1Shop Script
Apr 23, 2026
Jun 9, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the current_currency parameter.
1Virtuenetz
1Virtue Classifieds
Apr 23, 2026
Jun 9, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL commands via the category parameter.
1Virtuenetz
1Virtue News Manager
Apr 23, 2026
Jun 9, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL commands via the nid parameter.
1Jaredeckersley
1Mycars
Apr 23, 2026
Jun 9, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authuserid parameter.
1Virtuenetz
1Virtue Book Store
Apr 23, 2026
Jun 9, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL commands via the cid parameter.