← Back
CWE-89

20,587 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,587)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jiro
1Faq Manager Experience
Apr 23, 2026
Jun 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in read.asp in JiRo's FAQ Manager eXperience 1.0 allows remote attackers to execute arbitrary SQL commands via the fID parameter.
1Pilotcart
1Pilot Cart
Apr 23, 2026
Jun 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in pilot.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the article parameter in a kb action.
1Battleblog
1Battleblog
Apr 23, 2026
Jun 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in article.asp in Battle Blog 1.25 Build 4 and earlier allows remote attackers to execute arbitrary SQL commands via the entry parameter, a different vector than CVE-2008-2626.
1Realm Project
1Realm Cms
Apr 23, 2026
Jun 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the kwrd parameter in a kwl action to the...Show more
SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the kwrd parameter in a kwl action to the default URI.Show less
1Telephone
1Telephone Directory 2008
Apr 23, 2026
Jun 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) code parameter in a confirm_data action to edit1...Show more
Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) code parameter in a confirm_data action to edit1.php and the (2) id parameter to view_more.php.Show less
1Joomla
2Com News Portal
Joomla
Apr 23, 2026
Jun 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
1Powie
1Pnews
Apr 23, 2026
Jun 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the shownews parameter.
1Dcfm Blog
1Dcfm Blog
Apr 23, 2026
Jun 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in comments.php in DCFM Blog 0.9.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Insanelysimple2
1Isblog
Apr 23, 2026
Jun 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action. NOTE: the c...Show more
Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889.Show less
1Y Blog
1Yblog
Apr 23, 2026
Jun 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in yBlog 0.2.2.2 allow remote attackers to execute arbitrary SQL commands via (1) the q parameter to search.php, or the n parameter to (2) user.php or (3) uss.php.
1Smeweb
1Smeweb
Apr 23, 2026
Jun 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in catalog.php in SMEWeb 1.4b and 1.4f allow remote attackers to execute arbitrary SQL commands via the (1) idp and (2) category parameters.
1Joomla
1Com Joobb
Apr 23, 2026
Jun 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the forum parameter in a forum action to index...Show more
SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the forum parameter in a forum action to index.php.Show less
1Mebiblio
1Mebiblio
Apr 23, 2026
Jun 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/journal_change_mask.inc.php in meBiblio 0.4.7 allows remote attackers to execute arbitrary SQL commands via the JID parameter.
1Joomla
1Com Biblestudy
Apr 23, 2026
Jun 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a mediaplayer action to index.php.
1Kmrg Itb
1Otomigenx
Apr 23, 2026
Jun 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in OtomiGenX 2.2 allows remote attackers to execute arbitrary SQL commands via the userAccount parameter (aka the User Name field) to index.php. NOTE: some of these details are o...Show more
SQL injection vulnerability in login.php in OtomiGenX 2.2 allows remote attackers to execute arbitrary SQL commands via the userAccount parameter (aka the User Name field) to index.php. NOTE: some of these details are obtained from third party information.Show less
1Bearrivernet.net
1I Pos Internet Pay Online Store
Apr 23, 2026
Jun 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.asp in I-Pos Internet Pay Online Store 1.3 Beta and earlier allows remote attackers to execute arbitrary SQL commands via the item parameter.
1Joomla
2Com Joomradio
Joomla
Apr 23, 2026
Jun 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) show_radio or (2) show_video ac...Show more
Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) show_radio or (2) show_video action to index.php.Show less
1Joomla
2Com Acctexp
Joomla
Apr 23, 2026
Jun 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the usage parameter in a subscribe action to index.php.
1Joomla
1Com Jb2
Apr 23, 2026
Jun 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter in a category action to index.php.
1Lifetype
1Lifetype
Apr 23, 2026
Jun 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitrary SQL commands via the albumId parameter in a ViewAlbum action to index.php.