← Back
CWE-89

20,614 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,614)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webfileexplorer
1Web File Explorer
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Aquacms
1Aqua Cms
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/functions/base.php and...Show more
Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/functions/base.php and the (2) username parameter to admin/index.php.Show less
1Abk Soft
1Ablespace
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to events_view.php and the (2) id parameter to events_clndr_view.php.
1Cmscout
1Cmscout
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in...Show more
Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php.Show less
1Ajsquare
1Aj Article
Apr 23, 2026
Apr 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName parameter (aka the username field).
1Deltascripts
1Php Links
Apr 23, 2026
Apr 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka the admin field).
1Michael Fritz
1Worldcup
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in TARGET-E WorldCup Bets (worldcup) 2.0.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
1Manu Oehler
1Toto
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Fussballtippspiel (toto) 0.1.1 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
1Frank Naegler
1Timtab Sociable
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in TIMTAB social bookmark icons (timtab_sociable) 2.0.4 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
1Fr.simon Rundell
1Ste Prayer
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Random Prayer (ste_prayer) 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
1Sebastian Baumann
1Sb Downloader
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Download system (sb_downloader) extension 0.1.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
1Fr.simon Rundell
1Pd Trainingcourses
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Diocese of Portsmouth Training Courses (pd_trainingcourses) extension 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
1Diocese Of Portsmouth
1Pd Calendar Today
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Diocese of Portsmouth Calendar Today (pd_calendar_today) extension 0.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
1Kevin Renskers
1Dmmjobcontrol
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in JobControl (dmmjobcontrol) 1.15.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
1Jan Bednarik
1Cooluri
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in CoolURI (cooluri) 1.0.11 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
1Glfusion
1Glfusion
Apr 23, 2026
Apr 9, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the glf_session cookie parameter.
1Gravityboardx
1Gravity Board X
Apr 23, 2026
Apr 9, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to execute arbitrary SQL commands via the member_id parameter in a viewprofile action. NOTE: the board_id issue is alrea...Show more
SQL injection vulnerability in index.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to execute arbitrary SQL commands via the member_id parameter in a viewprofile action. NOTE: the board_id issue is already covered by CVE-2008-2996.2.Show less
1Quickersite
1Quickersite
Apr 23, 2026
Apr 8, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in asp/includes/contact.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary SQL commands via the sNickName parameter in a profile action to default.asp.
1Phpauctions
1Phpauctions
Apr 23, 2026
Apr 8, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the auction_id parameter, a different vector than CVE-2009-0...Show more
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the auction_id parameter, a different vector than CVE-2009-0106.Show less
1Alikonweb
1Com Bookjoomlas
Apr 23, 2026
Apr 7, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in sub_commententry.php in the BookJoomlas (com_bookjoomlas) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a comment action to i...Show more
SQL injection vulnerability in sub_commententry.php in the BookJoomlas (com_bookjoomlas) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a comment action to index.php.Show less