← Back
CWE-89

20,608 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,608)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1.matteoiammarrone
1S Cms
Apr 23, 2026
Mar 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Torben Sorensen
1Tinx/cms
Apr 23, 2026
Mar 9, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in system/rss.php in TinX/cms 3.x before 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Stewart Howe
1Celerbb
Apr 23, 2026
Mar 9, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewforum.php and (2) viewtopic.php.
1Phpkf
1Phpkf
Apr 23, 2026
Mar 9, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in forum_duzen.php in phpKF allows remote attackers to execute arbitrary SQL commands via the fno parameter.
1E107coders
1Macguru Blog Engine Plugin
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector than CVE-...Show more
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector than CVE-2008-2455. NOTE: it was later reported that 2.1.4 is also affected.Show less
1Blueriver
1Sava Cms
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.cfm in Blue River Interactive Group Sava CMS before 5.0.122 allows remote attackers to execute arbitrary SQL commands via the LinkServID parameter.
1Joomla
1Com Mycontent
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the MyContent (com_mycontent) component 1.1.13 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
1Mike Leeper
1Com Prayercenter
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_request action to index2...Show more
SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_request action to index2.php.Show less
1Hivemaker
1Hivemaker
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Comicshout
1Comicshout
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via the news_id parameter, a different vector than CVE-2008-2456.
1Psychostats
1Psychostats
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in PsychoStats 2.3, 2.3.1, and 2.3.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) weapon.php and (2) map.php.
1Socialsitegenerator
1Social Site Generator
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) sgc_id parameter to display_blog.php, (2) scm_mem_id parameter to social_my_p...Show more
Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) sgc_id parameter to display_blog.php, (2) scm_mem_id parameter to social_my_profile_download.php, and the (3) catid parameter to social_forum_subcategories.php.Show less
1Torrenttrader
1Torrenttrader
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in scrape.php in TorrentTrader before 2008-05-13 allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.
1Aj Square
1Aj Auction
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.
1Brian Wilson
1Ol'bookmarks
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a brain action.
1Greatclone
1Hotscripts Clone
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Jetik
1Jetik Web
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in sayfa.php in JETIK-WEB allows remote attackers to execute arbitrary SQL commands via the kat parameter.
1Yapbb
1Yapbb
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.
1Ausimods
1E Cart
Apr 23, 2026
Mar 5, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the CA parameter.
1Php Fusion
1Members Cv Module
Apr 23, 2026
Mar 5, 2009
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby paramete...Show more
SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter.Show less