← Back
CWE-89

20,631 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,631)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Allomani
1Audio & Video Library
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in Allomani Audio & Video Library (Songs & Clips version) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.
1Allomani
1Movies Library
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in Allomani Movies Library (Movies & Clips) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.
1Supercrackmunkey
1Simpleloginsys
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details ar...Show more
SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.Show less
1Technotoad
1Tt Web Site Manager
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in tt/index.php in TT Web Site Manager 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tt_name parameter. NOTE: some of these details...Show more
SQL injection vulnerability in tt/index.php in TT Web Site Manager 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tt_name parameter. NOTE: some of these details are obtained from third party information.Show less
1Boldfx
1Model Agency Manager Pro
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in photos.php in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allows remote attackers to execute arbitrary SQL commands via the album parameter.
1X10media
1Adult Script
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in report.php in x10 Adult Media Script 1.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Questions Answered
1Questions Answered
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from t...Show more
SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.Show less
1Junglescripts
1Ajax Short Url Script
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in x/login in JungleScripts Ajax Short Url Script allows remote attackers to execute arbitrary SQL commands via the username parameter.
1Paymentprocessorscript
1Ppscript
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in shop.htm in PaymentProcessorScript.net PPScript allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Limny
1Limny
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the CheckLogin function in includes/functions.php in Limny 1.01, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
1Andrews Web
1Aw Bannerad
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters. NOTE: some of these detai...Show more
Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters. NOTE: some of these details are obtained from third party information.Show less
1Gnudip
1Gnudip
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cgi-bin/gnudip.cgi in GnuDIP 2.1.1 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party informati...Show more
SQL injection vulnerability in cgi-bin/gnudip.cgi in GnuDIP 2.1.1 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.Show less
1Bob Jewell
1Discloser
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Discloser 0.0.4 rc2 allows remote attackers to execute arbitrary SQL commands via the more parameter.
1Templateplazza
1Com Tpjobs
Apr 29, 2026
Mar 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the TPJobs (com_tpjobs) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_c[] parameter in a resadvsearch action to index.php.
1Mitchell Sleeper
1L4d Stats
Apr 29, 2026
Mar 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in player.php in Left 4 Dead (L4D) Stats 1.1 allows remote attackers to execute arbitrary SQL commands via the steamid parameter.
1Phpcityportal
1Phpcityportal
Apr 29, 2026
Mar 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) video_show.php, (2) spotlight_detail.php, (3) real_estate_details.php, and (4)...Show more
Multiple SQL injection vulnerabilities in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) video_show.php, (2) spotlight_detail.php, (3) real_estate_details.php, and (4) auto_details.php.Show less
1Scripteverkauf
1Domain Verkaus And Auktions Portal
Apr 29, 2026
Mar 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in phppool media Domain Verkaus and Auktions Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Jorik Berkepas
1Phpmylogon
Apr 29, 2026
Mar 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in phpmylogon.php in PhpMyLogon 2 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
1Geekhelps
1Admp
Apr 29, 2026
Mar 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in bannershow.php in Geekhelps ADMP 1.01 allows remote attackers to execute arbitrary SQL commands via the click parameter.
1Media Products
1Eros Webkatalog
Apr 29, 2026
Mar 16, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in start.php in Eros Webkatalog allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik action.