← Back
CWE-89

20,617 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Preprojects
1Pre Real Estate Listings
Apr 23, 2026
May 7, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the username1 parameter (aka the Admin field or Username field).
1Niclor
1Vibro School Cms
Apr 23, 2026
May 7, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_news.php in nicLOR Vibro-School-CMS allows remote attackers to execute arbitrary SQL commands via the nID parameter.
1Sfs Ez Pub
1Fsf Ex Pub
Apr 23, 2026
May 7, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in directory.php in Scripts For Sites (SFS) EZ Pub Site allows remote attackers to execute arbitrary SQL commands via the cat parameter.
1Qsix
1Blusky Cms
Apr 23, 2026
May 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in BluSky CMS allows remote attackers to execute arbitrary SQL commands via the news_id parameter in a read action.
1Icewarp
2Email Server
Webmail Server
Apr 23, 2026
May 5, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL...Show more
Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query.Show less
1Minddezign
1Photo Gallery
Apr 23, 2026
May 4, 2009
N/A· v4
N/A· v3
5.1 MEDIUM· v2
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action to the admin module in index.php, a different vector than...Show more
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action to the admin module in index.php, a different vector than CVE-2008-6788.Show less
1Minddezign
1Photo Gallery
Apr 23, 2026
May 4, 2009
N/A· v4
N/A· v3
5.1 MEDIUM· v2
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in an info action to index.php.
1Myiosoft
1Ajaxportal
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
1Keir Davis
1X Forum
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL commands, as demonstrated via the cookie_username parameter to Configure.php...Show more
SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL commands, as demonstrated via the cookie_username parameter to Configure.php.Show less
1Jeremy Powers
1Lizardware Cms
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in administrator/index.php in Lizardware CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the user.
1Intelliants
1Elitius
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to banner-details.php.
1Drupal
1News Page
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the News Page module 5.x before 5.x-1.2 for Drupal allows remote authenticated users, with News Page nodes create and edit privileges, to execute arbitrary SQL commands via the Include Word...Show more
SQL injection vulnerability in the News Page module 5.x before 5.x-1.2 for Drupal allows remote authenticated users, with News Page nodes create and edit privileges, to execute arbitrary SQL commands via the Include Words (aka keywords) field.Show less
1Tigerdms
1Tigerdms
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in login.php in Tiger Document Management System (DMS) allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
1Projectcms
1Projectcms
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in ProjectCMS 1.0 Beta allows remote attackers to execute arbitrary SQL commands via the sn parameter.
1Scripts For Sites
1Ez Adult Directory
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in directory.php in Scripts For Sites (SFS) EZ Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
1Scripts For Sites
1Ez Home Business Directory
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Home Business Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
1Scripts For Sites
1Ez Hosting Directory
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Hosting Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
1Scripts For Sites
1Ez Gaming Directory
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
1Scripts For Sites
1Ez Affiliate
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in directory.php in Scripts for Sites (SFS) SFS EZ Affiliate allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
1Phpnuke
1Sarkilar Module
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a showcontent action to modules.php.