← Back
CWE-89

20,627 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,627)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Logrover
1Logrover
Apr 23, 2026
Oct 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in login.asp (aka the login screen) in LogRover 2.3 and 2.3.3 on Windows allow remote attackers to execute arbitrary SQL commands via the (1) uname and (2) pword parameters. NOTE:...Show more
Multiple SQL injection vulnerabilities in login.asp (aka the login screen) in LogRover 2.3 and 2.3.3 on Windows allow remote attackers to execute arbitrary SQL commands via the (1) uname and (2) pword parameters. NOTE: some of these details are obtained from third party information.Show less
1Universe
1Universe Cms
Apr 23, 2026
Oct 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Radscripts
1Radbids
Apr 23, 2026
Oct 2, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in RadScripts RadBids Gold 4 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action, a different vector than CVE-2005-1074.
1Al4us
1Mymsg
Apr 23, 2026
Oct 2, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL commands via the uid parameter in a show action.
1Marcin Manek
1D.net Cms
Apr 23, 2026
Oct 1, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php; and allow remote authenticated administrators to execute arbitrary SQL...Show more
Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (2) edit_id and (3) _p parameter in a news action to dnet_admin/index.php.Show less
1Dataspheric
1Linkspheric
Apr 23, 2026
Oct 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter.
1Vastal
1Mmorpg Zone
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_news.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter. NOTE: the game_id vector is already covered by CVE-2008-4460...Show more
SQL injection vulnerability in view_news.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter. NOTE: the game_id vector is already covered by CVE-2008-4460.Show less
1Alibabaclone
1Alibaba Clone
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Bpowerhouse
1Bpholidaylettings
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in search.aspx in BPowerHouse BPHolidayLettings 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) rid and (2) tid parameters.
1Bpowerhouse
1Bpmusic
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter.
1Bpowerhouse
1Bpstudents
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in students.php in BPowerHouse BPStudents 1.0 allows remote attackers to execute arbitrary SQL commands via the test parameter in a preview action.
1Bpowerhouse
1Bpgames
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in BPowerHouse BPGames 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to main.php and (2) game_id parameter to game.php.
1Bpowerhouse
1Bplawyercasedocuments
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
1Hbcms
1Hbcms
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in php/update_article_hits.php in HBcms 1.7 allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
1Vastal
1Agent Zone
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_listing.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Vastal
1Dvd Zone
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the mag_id parameter, a different vector than CVE-2008-4465.
1Todor Lazarov
1T Htb Manager
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in index.php in T-HTB Manager 0.5, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a delete_category action,...Show more
Multiple SQL injection vulnerabilities in index.php in T-HTB Manager 0.5, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a delete_category action, (2) the name parameter in an update_category action, and other vectors.Show less
1Kinfusion
1Com Sportfusion
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Kinfusion SportFusion (com_sportfusion) component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail acti...Show more
SQL injection vulnerability in the Kinfusion SportFusion (com_sportfusion) component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.Show less
1Isygen
1Icrm Basic
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! allows remote attackers to execute arbitrary SQL commands via the p3 parameter to index.php. NOTE: the provenance of this info...Show more
SQL injection vulnerability in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! allows remote attackers to execute arbitrary SQL commands via the p3 parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Rick Estrada
1Com Mytube
Apr 23, 2026
Sep 28, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.