CWE-89
20,733 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,733)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cpa Lead Reward Script Project 1Cpa Lead Reward Script May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CPA Lead Reward Script allows SQL Injection via the username parameter. |
1Readymadeb2bscript 1Basic B2b Script May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter. |
1Bekirk 1Creative Management System Lite May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php. |
1Geniusocean 1Mymagazine Magazine & Blog Cms May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. |
Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. |
Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. |
1Rowindex 1Us Zip Codes Database Script May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter. |
Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter. |
1Arox 1School Erp Php Script May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter. |
1Protectedlinks 1Expiring Download Links May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter. |
SQL injection vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the graph parameter to module/capacity_per_label/index.ph...Show more |
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604. |
Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461. |
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php. |
Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php. |
1Softdatepro 1Dating Software May 13, 2026 Oct 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15971. |
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972. |
1Phpcityportal 1Phpcityportal May 13, 2026 Oct 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter. |
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category. |
1Contractorscripts 1Mybuildersite May 13, 2026 Oct 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter. |