← Back
CWE-89

20,638 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,638)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
12daybiz
1Multi Level Marketing Software
Apr 29, 2026
Jun 29, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in 2daybiz Multi Level Marketing (MLM) Software allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) index.php and (2) admin/index.php. NOTE:...Show more
Multiple SQL injection vulnerabilities in 2daybiz Multi Level Marketing (MLM) Software allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) index.php and (2) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Dacian Strain
1Com Jfaq
Apr 29, 2026
Jun 28, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in index.php in the JFaq (com_jfaq) component 1.2 for Joomla!, when magic_quotes_gpc is disabled, allow (1) remote attackers to execute arbitrary SQL commands via the id parameter,...Show more
Multiple SQL injection vulnerabilities in index.php in the JFaq (com_jfaq) component 1.2 for Joomla!, when magic_quotes_gpc is disabled, allow (1) remote attackers to execute arbitrary SQL commands via the id parameter, and (2) remote authenticated users with "Public Front-end" permissions to execute arbitrary SQL commands via the titlu parameter (title field). NOTE: some of these details are obtained from third party information.Show less
1Harmistechnology
1Com Jeajaxeventcalendar
Apr 29, 2026
Jun 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.
12daybiz
1Matrimonial Script
Apr 29, 2026
Jun 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in customprofile.php in 2daybiz Matrimonial Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
12daybiz
1Multi Level Marketing Software
Apr 29, 2026
Jun 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in viewnews.php in 2daybiz Multi Level Marketing (MLM) Software allows remote attackers to execute arbitrary SQL commands via the nwsid parameter.
12daybiz
1Web Template Software
Apr 29, 2026
Jun 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in customize.php in 2daybiz Web Template Software allows remote attackers to execute arbitrary SQL commands via the tid parameter.
12daybiz
1Video Community Portal Script
Apr 29, 2026
Jun 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in user-profile.php in 2daybiz Video Community Portal Script allows remote attackers to execute arbitrary SQL commands via the userid parameter.
1Tomacero
1Orohyip
Apr 29, 2026
Jun 25, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action.
1Jce Tech
1Overstock Script
Apr 29, 2026
Jun 25, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter.
1Jce Tech
1Shareasale Script
Apr 29, 2026
Jun 25, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.
12daybiz
1Video Community Portal Script
Apr 29, 2026
Jun 25, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter.
1Laubrotel
1G.cms Generator
Apr 29, 2026
Jun 24, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php.
1Anecms
1Anecms Blog
Apr 29, 2026
Jun 24, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.
1Activewebsoftwares
1Ewebquiz
Apr 29, 2026
Jun 21, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007-1706.
1Eicrasoft
1Eicra Realestate Script
Apr 29, 2026
Jun 21, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. NOTE: some of these details are obtained from third par...Show more
SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. NOTE: some of these details are obtained from third party information.Show less
1Pilotgroup
1Elms Pro
Apr 29, 2026
Jun 21, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary SQL commands via the course_id parameter.
1Dmxready
1Online Notebook Manager
Apr 29, 2026
Jun 21, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
1Arabportal
1Arab Portal
Apr 29, 2026
Jun 18, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the by parameter in the msearch action.
1Subdreamer
1Subdreamer
Apr 29, 2026
Jun 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/pages.php in Subdreamer CMS 3.x.x allows remote attackers to execute arbitrary SQL commands via the categoryids[] parameter in an update_pages action.
1Vunet
1Vu Web Visitor Analyst
Apr 29, 2026
Jun 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. NOTE: some of these details are obta...Show more
Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. NOTE: some of these details are obtained from third party information.Show less