← Back
CWE-89

20,677 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,677)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Softbb
1Softbb
May 6, 2026
Jan 15, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in redir_last_post_list.php in SoftBB 0.1.3 allows remote attackers to execute arbitrary SQL commands via the post parameter.
1Domphp
1Domphp
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitrary SQL commands via the ids parameter.
1Couponphp
1Couponphp
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execute arbitrary SQL commands via the (1) iDisplayLength or (2) iDisplayStart parameter to (a) comments_p...Show more
Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execute arbitrary SQL commands via the (1) iDisplayLength or (2) iDisplayStart parameter to (a) comments_paginate.php or (b) stores_paginate.php in admin/ajax/.Show less
1Oscommerce
1Online Merchant
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID paramete...Show more
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action.Show less
1Scriptbrasil
1Taboada Macronews
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
1Licensepal
1Arcticdesk
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the ticket grid in the admin interface in LicensePal ArcticDesk before 1.2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Ismail Fahmi
1Ganesha Digital Library
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Ganesha Digital Library (GDL) 4.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) download.php or (2) main.php.
1Mtouch Quiz Project
1Mtouch Quiz
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in question.php in the mTouch Quiz before 3.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the quiz parameter to wp-admin/edit.php.
1Itechscripts
1Itechclassifieds
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. NOTE: the CatID parameter is already covered by CVE-200...Show more
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. NOTE: the CatID parameter is already covered by CVE-2008-0685.Show less
1Pomm Project
1Pomm
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the LTree converter in Pomm before 1.1.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Sendy
1Sendy
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote attackers to execute arbitrary SQL commands via the i parameter.
1Sendy
1Sendy
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via the c parameter.
1Fluxbb
1Fluxbb
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to execute arbitrary SQL commands via the req_new_email parameter.
1Topicsviewer
1Topicsviewer
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) edit_block.php, (2) edit_cat.php, (3) edit_note.php, or (4) rmv_topic...Show more
Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) edit_block.php, (2) edit_cat.php, (3) edit_note.php, or (4) rmv_topic.php in admincp/.Show less
1Tecorange
1Simple E Document
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL commands via the username parameter.
1Welcart
1E Commerce
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the Welcart e-Commerce plugin 1.3.12 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) changeSort or (2) switch parameter in the usces_itemedit p...Show more
Multiple SQL injection vulnerabilities in the Welcart e-Commerce plugin 1.3.12 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) changeSort or (2) switch parameter in the usces_itemedit page to wp-admin/admin.php.Show less
1Phpjabbers
1Event Booking Calendar
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Strategy11
1Awp Classifieds
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.
1Maianscriptworld
1Maian Uploader
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/data_files/move.php in Maian Uploader 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Yourmembers Project
1Yourmembers
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ym_download_id parameter to...Show more
SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ym_download_id parameter to the default URI.Show less