← Back
CWE-89

20,640 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,640)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Alibabaclone
1Alibaba Clone B2b
Apr 29, 2026
Sep 27, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in countrydetails.php in Alibaba Clone B2B 3.4 allows remote attackers to execute arbitrary SQL commands via the es_id parameter.
1Mhproducts
1Mhp Downloadshop
Apr 29, 2026
Sep 27, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
1Mhproducts
1Pay Pal Shop Digital
Apr 29, 2026
Sep 27, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_item.php in MH Products Pay Pal Shop Digital allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
1Mhproducts
1Projekt Shop
Apr 29, 2026
Sep 27, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php.
1Mhproducts
1Easy Online Shop
Apr 29, 2026
Sep 27, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary SQL commands via the kat parameter.
1Phpwebscripts
1Ad Manager Pro
Apr 29, 2026
Sep 27, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in website-page.php in PHP Web Scripts Ad Manager Pro 3.0 allows remote attackers to execute arbitrary SQL commands via the pageId parameter.
1Mhproducts
1Download Center
Apr 29, 2026
Sep 27, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote attackers to execute arbitrary SQL commands via the Name parameter. NOTE: some of these details ar...Show more
SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote attackers to execute arbitrary SQL commands via the Name parameter. NOTE: some of these details are obtained from third party information.Show less
1Mercator
1Sentinel
Apr 29, 2026
Sep 22, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the login form in the web interface in Mercator SENTINEL 2.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Myrephp
1Myre Real Estate Software
Apr 29, 2026
Sep 15, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in findagent.php in MYRE Real Estate Software allows remote attackers to execute arbitrary SQL commands via the page parameter.
1Edgetechweb
1Event Registration
Apr 29, 2026
Sep 14, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action.
1Extensiondepot
1Com Jsupport
Apr 29, 2026
Sep 14, 2011
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote authenticated users, with Public Back-end permissions, to execute arbitrary SQL commands via the alpha parameter in a (...Show more
SQL injection vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote authenticated users, with Public Back-end permissions, to execute arbitrary SQL commands via the alpha parameter in a (1) listTickets or (2) listFaqs action to administrator/index.php.Show less
1Oneorzero
1Aims
Apr 29, 2026
Sep 14, 2011
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_s...Show more
Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types parameter in a show_item_search action in the search_management_manage subcontroller. NOTE: some of these details are obtained from third party information.Show less
1Cmsfaethon
1Cms Faethon
Apr 29, 2026
Sep 12, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL commands via the item parameter.
1Vlinks
1Vlinks
Apr 29, 2026
Sep 12, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Daman371
1Bloggeruniverse
Apr 29, 2026
Sep 12, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter and possibly other unspecified...Show more
SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter and possibly other unspecified vectors.Show less
1Ideacart
1Ideacart
Apr 29, 2026
Sep 12, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL commands via the cID parameter.
1Rubyonrails
2Rails
Ruby On Rails
Apr 29, 2026
Aug 29, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the quote_table_name method in the ActiveRecord adapters in activerecord/lib/active_record/connection_adapters/ in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x bef...Show more
Multiple SQL injection vulnerabilities in the quote_table_name method in the ActiveRecord adapters in activerecord/lib/active_record/connection_adapters/ in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allow remote attackers to execute arbitrary SQL commands via a crafted column name.Show less
1T Dreams
1Job Career Package
Apr 29, 2026
Aug 24, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Resumes/TD_RESUME_Indlist.asp in Techno Dreams (T-Dreams) Job Career Package 3.0 allows remote attackers to execute arbitrary SQL commands via the z_Residency parameter.
1T Dreams
1Cars Ads Package
Apr 29, 2026
Aug 24, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in processview.asp in Techno Dreams (T-Dreams) Cars Ads Package 2.0 allows remote attackers to execute arbitrary SQL commands via the key parameter.
1Snitz Communications
1Snitz Forums 2000
Apr 29, 2026
Aug 24, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to execute arbitrary SQL commands via the M_NAME parameter. NOTE: some of these details are obtained from third party inform...Show more
SQL injection vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to execute arbitrary SQL commands via the M_NAME parameter. NOTE: some of these details are obtained from third party information.Show less