← Back
CWE-89

20,733 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,733)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpa Lead Reward Script Project
1Cpa Lead Reward Script
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CPA Lead Reward Script allows SQL Injection via the username parameter.
1Readymadeb2bscript
1Basic B2b Script
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.
1Bekirk
1Creative Management System Lite
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.
1Geniusocean
1Mymagazine Magazine & Blog Cms
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
1Geniusocean
1News
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
1Geniusocean
1Newspaper
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
1Rowindex
1Us Zip Codes Database Script
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.
1Odallated
1Shareet
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.
1Arox
1School Erp Php Script
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
1Protectedlinks
1Expiring Download Links
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.
1Eyesofnetwork
1Eyesofnetwork
May 13, 2026
Oct 29, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the graph parameter to module/capacity_per_label/index.ph...Show more
SQL injection vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the graph parameter to module/capacity_per_label/index.php.Show less
1Zeescripts
1Zeebuddy
May 13, 2026
Oct 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604.
1Vastal
1Dating Zone
May 13, 2026
Oct 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461.
1Datacomponents
1Tpanel
May 13, 2026
Oct 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
1Sokial
1Sokial
May 13, 2026
Oct 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.
1Softdatepro
1Dating Software
May 13, 2026
Oct 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15971.
1Softdatepro
1Same Date Pro
May 13, 2026
Oct 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972.
1Phpcityportal
1Phpcityportal
May 13, 2026
Oct 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.
1Pilotgroup
1Allsharevideo
May 13, 2026
Oct 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.
1Contractorscripts
1Mybuildersite
May 13, 2026
Oct 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.