← Back
CWE-89

20,733 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,733)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zuuse
1Beims Contractorweb .net
May 13, 2026
Dec 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.
1Paid To Read Script Project
1Paid To Read Script
May 13, 2026
Dec 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.
1Phpautoclassifiedscript
1Bus Booking Script
May 13, 2026
Dec 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
1Lynda Clone Project
1Lynda Clone
May 13, 2026
Dec 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
1Dedecms
1Dedecms
May 13, 2026
Dec 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
1Dedecms
1Dedecms
May 13, 2026
Dec 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.
1Boxug
1Trape
May 13, 2026
Dec 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu pa...Show more
Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, the /register lat parameter, the /register lon parameter, the /register org parameter, the /register query parameter, the /register region parameter, the /register regionName parameter, the /register timezone parameter, the /register vId parameter, the /register zip parameter, or the /tping id parameter.Show less
1Techno Portfolio Management Panel Project
1Techno Portfolio Management Panel
May 13, 2026
Dec 15, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Techno - Portfolio Management Panel through 2017-11-16 allows SQL Injection via the panel/search.php s parameter.
1Apache
1Fineract
May 13, 2026
Dec 14, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch'...Show more
In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endpoints is not sanitized and appended directly to the query.Show less
1Entrepreneur Dating Script Project
1Entrepreneur Dating Script
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.
1Basic Job Site Script Project
1Basic Job Site Script
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
1Resume Clone Script Project
1Resume Clone Script
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
1Advanced World Database Project
1Advanced World Database
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
1Muslim Matrimonial Script Project
1Muslim Matrimonial Script
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
1Groupon Clone Script Project
1Groupon Clone Script
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
1Car Rental Script Project
1Car Rental Script
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
1Mlm Forced Matrix Project
1Mlm Forced Matrix
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
1Mlm Forex Market Plan Script Project
1Mlm Forex Market Plan Script
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.
1Single Theater Booking Script Project
1Single Theater Booking Script
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
1Multiplex Movie Theater Booking Script Project
1Multiplex Movie Theater Booking Script
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.