← Back
CWE-89

20,608 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,608)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mountaingrafix
1Easylink
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a show action.
1Plaincart
1Plaincart
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands via the p parameter.
1Dieselscripts
1Diesel Pay
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the area parameter in a browse action.
1Dieselscripts
1Diesel Job Site
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitrary SQL commands via the job_id parameter.
1Akirapowered
1Image Gallery
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote attackers to execute arbitrary SQL commands via the image parameter in an image-de...Show more
SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote attackers to execute arbitrary SQL commands via the image parameter in an image-detail action.Show less
1Mevin
1Basic Php Events Lister
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in event.php in Mevin Productions Basic PHP Events Lister 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Fr.simon Rundell
1Pd Churchsearch
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Diocese of Portsmouth Church Search (pd_churchsearch) extension before 0.1.1, and 0.2.10 and earlier 0.2.x versions, an extension for TYPO3, allows remote attackers to execute arbitrary...Show more
SQL injection vulnerability in the Diocese of Portsmouth Church Search (pd_churchsearch) extension before 0.1.1, and 0.2.10 and earlier 0.2.x versions, an extension for TYPO3, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.Show less
1Kurt Gusbeth
1Myquizpoll
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the My quiz and poll (myquizpoll) extension before 0.1.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Fr.simon Rundell
1Ste Prayer2
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Random Prayer 2 (ste_prayer2) extension before 0.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Mirko Werner
1Mw Random Objects
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Simple Random Objects (mw_random_objects) extension 1.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Autobeuser
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the auto BE User Registration (autobeuser) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Dieter Mayer
1Fe Address Edit
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the FE address edit for tt_address & direct mail (dmaddredit) extension 0.4.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Walnutstreet
1Cgswigmore
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Swigmore institute (cgswigmore) extension before 0.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Martin Helmich
1Hbook
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the HBook (h_book) extension 2.3.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
16rbscript
16rbscript
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands via the singerid parameter in a singers action.
1Oceandir
1Oceandir
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Jportal
1Jportal
Apr 23, 2026
Mar 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2004-2036 or CVE-2005-3509.
1Amunak
1Blue Eye Cms
Apr 23, 2026
Mar 12, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the BlueEyeCMS_login cookie parameter.
1Roman Bogorodskiy
1Nforum
Apr 23, 2026
Mar 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in nForum 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to showtheme.php and the (2) user parameter to userinfo.php.
1Josema Enzo
1Isiajax
Apr 23, 2026
Mar 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ejemplo/paises.php in isiAJAX 1 allows remote attackers to execute arbitrary SQL commands via the id parameter.