← Back
CWE-89

20,610 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,610)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nick Jenkin
1Newshowler
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in NewsHOWLER 1.03 Beta allows remote attackers to execute arbitrary SQL commands via the news_user cookie parameter.
1Kamads
1Bloginator
Apr 23, 2026
Mar 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in articleCall.php in Bloginator 1A allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Igniterealtime
1Openfire
Apr 23, 2026
Mar 23, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via the type parameter to sipark-log-summary.jsp.
1Yap
1Yap Blog
Apr 23, 2026
Mar 20, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) image_id parameter to comments.php, and remote authenticated administrators to execute arbitra...Show more
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) image_id parameter to comments.php, and remote authenticated administrators to execute arbitrary SQL commands via the (2) user parameter in a modif action to admin/index.php.Show less
1Drupal
1Tasklist
Apr 23, 2026
Mar 20, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
SQL injection vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via values in the URI.
1Deluxebb
1Deluxebb
Apr 23, 2026
Mar 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder parameter, a different vector than CVE-2005-2989 and CVE-2006-2503.
1Yabsoft
1Advanced Image Hosting Script
Apr 23, 2026
Mar 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in gallery_list.php in YABSoft Advanced Image Hosting (AIH) Script 2.3 allows remote attackers to execute arbitrary SQL commands via the gal parameter.
1Opencart
1Opencart
Apr 23, 2026
Mar 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.
1Kimwebsites
1Kim Websites
Apr 23, 2026
Mar 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in login.php in Kim Websites 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
1Beerwin
1Phplinkadmin
Apr 23, 2026
Mar 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Beerwin PHPLinkAdmin 1.0 allow remote attackers to execute arbitrary SQL commands via the linkid parameter to edlink.php, and unspecified other vectors.
1Phpcomasy
1Phpcomasy
Apr 23, 2026
Mar 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in phpComasy 0.9.1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter.
1Fahlstad
1Fmoblog Plugin
Apr 23, 2026
Mar 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: some of these details are obtained fr...Show more
SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: some of these details are obtained from third party information.Show less
1Ismail Fahmi
1Ganesha Digital Library
Apr 23, 2026
Mar 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in functions/browse.php in Ganesha Digital Library (GDL) 4.0 and 4.2 allows remote attackers to execute arbitrary SQL commands via the node parameter in a browse action to gdl.php.
1Xlinesoft
1Phprunner
Apr 23, 2026
Mar 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) use...Show more
Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php.Show less
1Huseyin Bora Abaci
1Com Myalbum
Apr 23, 2026
Mar 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the album parameter to index.php.
1Softcomplex
1Php Image Gallery
Apr 23, 2026
Mar 18, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the Admin field in a login action.
1Digiappz
1Digiaffiliate
Apr 23, 2026
Mar 18, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin and (2) password fields.
1Softcomplex
1Php Image Gallery
Apr 23, 2026
Mar 18, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary SQL commands via the ctg parameter.
1Mole Group
1Taxi Calc Dist Script
Apr 23, 2026
Mar 18, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attackers to execute arbitrary SQL commands via the user field.
1Joomprod
1Com Versioning
Apr 23, 2026
Mar 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.