← Back
CWE-89

20,621 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,621)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jfusion
1Com Jfusion
Apr 23, 2026
Aug 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the JFusion (com_jfusion) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
1Arabportal
1Arab Portal
Apr 23, 2026
Aug 17, 2009
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in forum.php in Arab Portal 2.x, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the qc parameter in an addcomment action, a differen...Show more
SQL injection vulnerability in forum.php in Arab Portal 2.x, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the qc parameter in an addcomment action, a different vector than CVE-2006-1666.Show less
1Ajsquare
1Aj Matrix Dna
Apr 23, 2026
Aug 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action.
1Garagesalesjunkie
1Garagesales Script
Apr 23, 2026
Aug 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL commands via the key parameter.
1Sellatsite.com
1Smart Asp Survey
Apr 23, 2026
Aug 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.
1Phparcadescript
1Phparcadescript
Apr 23, 2026
Aug 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Php Paid4mail
1Php Paid4mail
Apr 23, 2026
Aug 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in paidbanner.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary SQL commands via the ID parameter.
1Ibm
1Websphere Partner Gateway
Apr 23, 2026
Aug 13, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the console in IBM WebSphere Partner Gateway (WPG) Enterprise 6.0 before FP8, 6.1 before FP3, 6.1.1 before FP2, and 6.2 before FP1 allows remote authenticated users to execute arbitrary SQL...Show more
SQL injection vulnerability in the console in IBM WebSphere Partner Gateway (WPG) Enterprise 6.0 before FP8, 6.1 before FP3, 6.1.1 before FP2, and 6.2 before FP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.Show less
1Ubbcentral
1Ubb.threads
Apr 23, 2026
Aug 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.
1Pligg
1Pligg Cms
Apr 23, 2026
Aug 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in submit.php in Pligg CMS 9.9.5 allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.
1X7 Group
1X7 Chat
Apr 23, 2026
Aug 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the login page in X7 Chat 2.0.5 allows remote attackers to execute arbitrary SQL commands via the password field.
1Cms.maury91
1Maurycms
Apr 23, 2026
Aug 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Rss.php in MauryCMS 0.53.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter.
1Webhost Panel
1Bankoi Webhosting Control Panel
Apr 23, 2026
Aug 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
1Turnkeyforms
1Web Hosting Directory
Apr 23, 2026
Aug 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQL commands via the password field.
1Sun Jester
1Opennews
Apr 23, 2026
Aug 11, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
1Joomla
1Com Content
Apr 23, 2026
Aug 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a blogcategory action to index.php.
1Exoscripts
1Exophpdesk
Apr 23, 2026
Aug 7, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQL commands via the username (user parameter).
1Brewblogger
1Brewblogger
Apr 23, 2026
Aug 6, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands vi...Show more
SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginUsername parameter to includes/logincheck.inc.php. NOTE: some of these details are obtained from third party information.Show less
12532gigs
12532gigs
Apr 23, 2026
Aug 6, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) pass...Show more
Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, as accessible from a form generated by index.php.Show less
1Cs Cart
1Cs Cart
Apr 23, 2026
Aug 5, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute arbitrary SQL commands via the sort_order parameter in a reward_points...Show more
SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute arbitrary SQL commands via the sort_order parameter in a reward_points.userlog action to index.php, a different vulnerability than CVE-2005-4429.2.Show less