← Back
CWE-89

20,640 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,640)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bouzouste
1Primitive Cms
Apr 29, 2026
Sep 22, 2010
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in cms_write.php in Primitive CMS 1.0.9 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) title and (2) menutitle parameters. NOTE: this can be...Show more
Multiple SQL injection vulnerabilities in cms_write.php in Primitive CMS 1.0.9 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) title and (2) menutitle parameters. NOTE: this can be leveraged with CVE-2010-3483 to conduct attacks without authentication.Show less
1Apphp
1Php Microcms
Apr 29, 2026
Sep 22, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variable...Show more
Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variables, possibly related to include/classes/Login.php. NOTE: some of these details are obtained from third party information. NOTE: the password vector might not be vulnerable.Show less
1Boutikone
1Boutikone
Apr 29, 2026
Sep 22, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in list.php in BoutikOne 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
1E Soft24
1Banner Exchange Script
Apr 29, 2026
Sep 22, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbitrary SQL commands via the targetid parameter.
1E Xoopport
1Samsara
Apr 29, 2026
Sep 17, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial module is enabled, allows remote attackers to execute arbitrary SQL commands via the secid parameter in a...Show more
SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial module is enabled, allows remote attackers to execute arbitrary SQL commands via the secid parameter in a listarticles action.Show less
1Endonesia
1Endonesia
Apr 29, 2026
Sep 17, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Publisher module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printarticle action to mod.php, a different vector than CVE-2007...Show more
SQL injection vulnerability in the Publisher module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printarticle action to mod.php, a different vector than CVE-2007-3394.Show less
1Getsymphony
1Symphony
Apr 29, 2026
Sep 17, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[recipient] parameter to about/. NOTE: some...Show more
SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[recipient] parameter to about/. NOTE: some of these details are obtained from third party information.Show less
1Intermesh
1Group Office
Apr 29, 2026
Sep 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a category action.
1Freka
1Yr Verdata
Apr 29, 2026
Sep 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Yr Weatherdata module for Drupal 6.x before 6.x-1.6 allows remote attackers to execute arbitrary SQL commands via the sorting method.
1Solventus
1Com Jgen
Apr 29, 2026
Sep 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the JGen (com_jgen) component 0.9.33 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
1Eshtery.she7ata
1Eshtery Cms
Apr 29, 2026
Sep 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in eshtery CMS (aka eshtery.com) allow remote attackers to execute arbitrary SQL commands via the (1) Criteria field in an unspecified form related to catlgsearch.aspx or (2) user n...Show more
Multiple SQL injection vulnerabilities in eshtery CMS (aka eshtery.com) allow remote attackers to execute arbitrary SQL commands via the (1) Criteria field in an unspecified form related to catlgsearch.aspx or (2) user name to an unspecified form related to adminlogin.aspx.Show less
1Seagullproject.org
1Seagull
Apr 29, 2026
Sep 3, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH...Show more
SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH_INFO.Show less
1Jextn
1Com Jefaqpro
Apr 29, 2026
Sep 3, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via category categorylist operations with (1) the catid paramet...Show more
Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via category categorylist operations with (1) the catid parameter or (2) the catid parameter in a lists action.Show less
1Galeriashqip
1Galeriashqip
Apr 29, 2026
Sep 3, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in GaleriaSHQIP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the album_id parameter. NOTE: some of these details are obta...Show more
SQL injection vulnerability in index.php in GaleriaSHQIP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the album_id parameter. NOTE: some of these details are obtained from third party information.Show less
1Ifdefined
1Bugtracker.net
Apr 29, 2026
Aug 31, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search.aspx in BugTracker.NET 3.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via a custom field to the search page.
1Script Shop24
1Lm Starmail Paidmail
Apr 29, 2026
Aug 25, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
1Websitesrus
1Accessories Me Php Affiliate Script
Apr 29, 2026
Aug 25, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute arbitrary SQL commands via the Go parameter.
1Irokez
1Irokez Cms
Apr 29, 2026
Aug 25, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the select function in Irokez CMS 0.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to the default URI.
1Keil Software
1Photokorn Gallery
Apr 29, 2026
Aug 25, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in search.php in Photokorn Gallery 1.81 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) where[], (2) sort, (3) order, and (4) Match parameters.
1Cisco
1Wireless Control System Software
Apr 29, 2026
Aug 17, 2010
N/A· v4
N/A· v3
9.0 HIGH· v2
SQL injection vulnerability in Cisco Wireless Control System (WCS) 6.0.x before 6.0.196.0 allows remote authenticated users to execute arbitrary SQL commands via vectors related to the ORDER BY clause of the Client List...Show more
SQL injection vulnerability in Cisco Wireless Control System (WCS) 6.0.x before 6.0.196.0 allows remote authenticated users to execute arbitrary SQL commands via vectors related to the ORDER BY clause of the Client List screens, aka Bug ID CSCtf37019.Show less