← Back
CWE-89

20,642 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,642)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ypninc
1Jokescript
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in YPNinc JokeScript allows remote attackers to execute arbitrary SQL commands via the ypncat_id parameter.
1Wikiwebhelp
1Wiki Web Help
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in handlers/getpage.php in Wiki Web Help 0.28 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Brotherscripts
1Business Directory
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Webmaster Tips
1Com Wmtpic
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the webmaster-tips.net Flash Gallery (com_wmtpic) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
1Oneorzero
1Aims
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the cookieName variable.
1Infor
2Eclient
Enspire Distribution Management Solution
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in eClient 7.3.2.3 in Enspire Distribution Management Solution 7.3.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Simplemachines
1Smf
Apr 29, 2026
Oct 24, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via vectors involving a (1) HTML entity or (2) display nam...Show more
Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via vectors involving a (1) HTML entity or (2) display name. NOTE: some of these details are obtained from third party information.Show less
1Xia Zuojie
1Nexusphp
Apr 29, 2026
Oct 21, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in thanks.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Lockon
1Ec Cube
Apr 29, 2026
Oct 21, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in data/class/SC_Query.php in EC-CUBE 2.11.0 through 2.11.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Atcom
1Netvolution
Apr 29, 2026
Oct 21, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.
1Atcom
1Netvolution
Apr 29, 2026
Oct 21, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL commands via the artID parameter.
1Atcom
1Netvolution
Apr 29, 2026
Oct 21, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bpe_nid parameter.
1Hulihanapplications
1Hulihan Bxr
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in folder/list in Hulihan BXR 0.6.8 allows remote attackers to execute arbitrary SQL commands via the order_by parameter.
1Dev Team Typoheads
1Webkitpdf
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Webkit PDFs (webkitpdf) extension before 1.1.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Preproject
1Pre Podcast Portal
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the login feature in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the password parameter.
1Pradoportal
1Prado Portal
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Prado Portal 1.2.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
1Nadine Schwingler
1Ke Questionnaire
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Questionnaire (ke_questionnaire) extension before 2.2.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Php Programs
1Apboard Developers Apboard
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in board/board.php in APBoard Developers APBoard 2.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-3078.
1Gambio
1Xt\
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in product_reviews_info.php in xt:Commerce Gambio 2008 allows remote attackers to execute arbitrary SQL commands via the products_id parameter.
1Joachim Ruhs
1Festat
Apr 29, 2026
Oct 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the FE user statistic (festat) extension before 0.2.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.