← Back
CWE-89

20,589 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,589)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mywebland
1Mybloggie
Apr 23, 2026
Jul 9, 2008
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated...Show more
Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the post_id parameter in an edit action to admin.php.Show less
1Mybb
1Mybb
Apr 23, 2026
Jul 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in inc/datahandler/user.php in MyBB before 1.2.13 has unknown impact and attack vectors related to the $user['language'] variable, probably related to SQL injection.
1Courier Mta
1Courtier Authlib
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
5.1 MEDIUM· v2
SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote...Show more
SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors.Show less
1Typo3
1Codeon Petition Extension
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Codeon Petition (cd_petition) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Support View Extension
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Support view (ext_tbl) extension 0.0.102 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Branchenbuch Extension
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Branchenbuch (aka Yellow Pages o (mh_branchenbuch) extension 0.8.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Sql Frontend Extension
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Pinboard Extension
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Pinboard extension 0.0.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1News Calendar Extension
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the News Calendar (newscalendar) extension 1.0.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Dam Frontend Extension
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Address Directory
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Address Directory (sp_directory) extension 0.2.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Xchangeboard
1Xchangeboard
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to execute arbitrary SQL commands via the boardID parameter.
1Rss Aggregator
1Rss Aggregator
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in RSS-aggregator 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) IdFlux parameter to admin/fonctions/supprimer_flux.php and the (2) IdTag parameter to admi...Show more
Multiple SQL injection vulnerabilities in RSS-aggregator 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) IdFlux parameter to admin/fonctions/supprimer_flux.php and the (2) IdTag parameter to admin/fonctions/supprimer_tag.php.Show less
1Efes Tech Shop
1Efes Tech Shop
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.asp in EfesTECH Shop 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in an urunler action.
1Vangogh Web Cms
1Vangogh Web Cms
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in get_article.php in VanGogh Web CMS 0.9 allows remote attackers to execute arbitrary SQL commands via the article_ID parameter to index.php.
1Oneclick Cms
1Oneclick Cms
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Plx Web Studio
1Plx Ad Trader
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ad.php in plx Ad Trader 3.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter in a redir action.
1Drupal
2Aggregation Module
Drupal
Apr 23, 2026
Jul 3, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Gravityboardx
1Gravity Board X
Apr 23, 2026
Jul 3, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in index.php in Gravity Board X (GBX) 2.0 Beta, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchquery parameter in a ge...Show more
Multiple SQL injection vulnerabilities in index.php in Gravity Board X (GBX) 2.0 Beta, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchquery parameter in a getsearch action, and the (2) board_id parameter in a viewboard action.Show less
1Phpeasydata
1Phpeasydata
Apr 23, 2026
Jul 3, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to execute arbitrary SQL commands via (1) the annuaire parameter to annuaire.php or (2) the username field in admin/login.php.