← Back
CWE-89

20,640 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,640)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vasthtml
1Forum Server
Apr 29, 2026
Feb 21, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) search_max parameter in a search...Show more
Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) search_max parameter in a search action to index.php, which is not properly handled by wpf.class.php, (2) id parameter in an editpost action to index.php, which is not properly handled by wpf-post.php, or (3) topic parameter to feed.php.Show less
1Rubyonrails
1Rails
Apr 29, 2026
Feb 21, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.
1Aretimes
1Com Maianmedia
Apr 29, 2026
Feb 16, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Maian Media Silver (com_maianmedia) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a music action to index.php.
1Raemedia
1Real Estate Single And Multi Agent System
Apr 29, 2026
Feb 16, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL commands via the probe parameter to (1) multi/city.asp in the Multi Ag...Show more
Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL commands via the probe parameter to (1) multi/city.asp in the Multi Agent System and (2) resulttype.asp in the Single Agent System.Show less
1Hotwebscripts
1Hotweb Rentals
Apr 29, 2026
Feb 16, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in resorts.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropResort parameter.
1Gatesoft
1Docusafe
Apr 29, 2026
Feb 16, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ECO.asp in GateSoft DocuSafe 4.1.0 and 4.1.2 allows remote attackers to execute arbitrary SQL commands via the ECO_ID parameter. NOTE: some of these details are obtained from third party i...Show more
SQL injection vulnerability in ECO.asp in GateSoft DocuSafe 4.1.0 and 4.1.2 allows remote attackers to execute arbitrary SQL commands via the ECO_ID parameter. NOTE: some of these details are obtained from third party information.Show less
1Ecommercemax
1Digital Goods Seller
Apr 29, 2026
Feb 16, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in shoppingcart.asp in Ecommercemax Solutions Digital-goods seller (DGS) 1.5 allows remote attackers to execute arbitrary SQL commands via the d parameter.
1Modxcms
1Evolution
Apr 29, 2026
Feb 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.
1Mhproducts
1Immo Makler
Apr 29, 2026
Feb 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Harmistechnology
1Com Jeauto
Apr 29, 2026
Feb 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component before 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to the view item page.
1Anserv
1Php Low Bids
Apr 29, 2026
Jan 25, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in viewfaqs.php in PHP LOW BIDS allows remote attackers to execute arbitrary SQL commands via the cat parameter.
1Phpcms
1Phpcms 2008
Apr 29, 2026
Jan 25, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time parameter in a get action.
1Phpcms
1Phpcms 2008
Apr 29, 2026
Jan 25, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the modelid parameter to flash_upload.php.
1Gallarific
1Php Photo Gallery Script
Apr 29, 2026
Jan 20, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in gallery.php in Gallarific PHP Photo Gallery script 2.1 and possibly other versions allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Epromptc
1Betmore Site Suite
Apr 29, 2026
Jan 20, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in mainx_a.php in E-PROMPT C BetMore Site Suite 4.0 through 4.2.0 allows remote attackers to execute arbitrary SQL commands via the bid parameter.
1Jikaka
1Teams Structure Module
Apr 29, 2026
Jan 20, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in team.php in the Teams Structure module 3.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the team_id parameter.
1Joomtraders
1Com Allcinevid
Apr 29, 2026
Jan 20, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the allCineVid component (com_allcinevid) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
1Awbs
1Advanced Webhost Billing System
Apr 29, 2026
Jan 20, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the oid parameter in an add_other action.
1Hotwebscripts
1Hotweb Rentals
Apr 29, 2026
Jan 20, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PageId parameter. NOTE: the provenance of this information is unknown; the det...Show more
SQL injection vulnerability in default.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PageId parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Fxwebdesign
1Com Jradio
Apr 29, 2026
Jan 20, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors.