← Back
CWE-89

20,642 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,642)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cramerdev
1Digital Interchange Calendar
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter.
1Harmistechnology
1Com Jesubmit
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the JExtensions JE Story Submit (com_jesubmit) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.
1Cramerdev
1Document Library
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intGroupID parameter.
1Netartmedia
1Iboutique
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
12daybiz
1Online Classified Script
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.
1Eliteladders
1Elite Gaming Ladders
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in stats.php in Elite Gaming Ladders 3.0 allows remote attackers to execute arbitrary SQL commands via the account parameter.
1Eliteladders
1Elite Gaming Ladders
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in matchdb.php in Elite Gaming Ladders 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the match parameter.
12daybiz
1Network Community Script
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_photo.php in 2daybiz Network Community Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.
1Eliteladders
1Elite Gaming Ladders
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter.
1Mckenziecreations
1Virtual Real Estate Manager
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter.
1David Noguera Gutierrez
1Dalogin
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in new.php in DaLogin 2.2 and 2.2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.
1Schoolmation
1Schoolmation
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to execute arbitrary SQL commands via the session parameter.
1Ut Files
1Utstats
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action.
1Denaliintranet
1Brightsuite Groupware
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to execute arbitrary SQL commands via the ContactID parameter.
1Emophp
1Emo Realty Manager
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in googlemap/index.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the cat1 parameter.
12daybiz
1Polls Script
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in searchvote.php in 2daybiz Polls (aka Advanced Poll) Script allows remote attackers to execute arbitrary SQL commands via the category parameter.
1Joe Pieruccini
1Mclogin System
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the myusername parameter (aka Username field) in a do_login action. NOTE:...Show more
SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the myusername parameter (aka Username field) in a do_login action. NOTE: some of these details are obtained from third party information.Show less
1Olykit
1Swoopo Clone 2010
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in OlyKit Swoopo Clone 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter in a product action.
1Autartica
1Com Autartimonial
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the limit parameter in an autartimonial action to index.php....Show more
SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the limit parameter in an autartimonial action to index.php. NOTE: some of these details are obtained from third party information.Show less
1Esoftpro
1Online Contact Manager
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view.php in esoftpro Online Contact Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.