← Back
CWE-89

20,608 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,608)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Andrew Freed
1Quotebook
Apr 23, 2026
Mar 5, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1) MyBox and (2) selectFavorites parameters to (a) quotes.php and the (3) QuoteName and (4) QuoteText...Show more
Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1) MyBox and (2) selectFavorites parameters to (a) quotes.php and the (3) QuoteName and (4) QuoteText parameters to (b) quotesadd.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Xatrix
1Xguestbook
Apr 23, 2026
Mar 4, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter.
1Simple Cmms
1Simplecmms
Apr 23, 2026
Mar 4, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in SimpleCMMS before 0.1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Cs Cart
1Cs Cart
Apr 23, 2026
Mar 4, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter.
1Tombstone
1Smnews
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in the smNews example script for txtSQL 2.2 Final allows remote attackers to execute arbitrary SQL commands via the username parameter.
11scripts
1Z1exchange
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Nexusjnr
1Jbook
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the username (user parameter).
1Ocean12tech
1Membership Manager Pro
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the d...Show more
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Aliensoftcorp
1Rae Media Contact Management
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterprise allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: some...Show more
SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterprise allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: some of these details are obtained from third party information.Show less
1Drupal
1Storm
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute...Show more
SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors.Show less
1Bcoos
1Bcoos
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
4.6 MEDIUM· v2
SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses module permissions to execute arbitrary SQL commands via the cid paramet...Show more
SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses module permissions to execute arbitrary SQL commands via the cid parameter.Show less
1Activewebsoftwares
1Active Web Helpdesk
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
1Mxmania
1Gallery Mx
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
1Mxmania
1Calendar Mx Professional
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
1Nexusjnr
1Jbook
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the password (pass parameter).
1Ocean12tech
1Faq Manager Pro
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.asp in Ocean12 FAQ Manager Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a Cat action. NOTE: some of these details are obtained from thi...Show more
SQL injection vulnerability in default.asp in Ocean12 FAQ Manager Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a Cat action. NOTE: some of these details are obtained from third party information.Show less
1Ocean12tech
1Membership Manager Pro
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the username (Username parameter).
1Ocean12tech
1Contact Manager Pro
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitrary SQL commands via the Sort parameter.
1Chipmunk Scripts
1Chipmunk Guestbook
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Chipmunk Guestbook 1.4m allows remote attackers to execute arbitrary SQL commands via the start parameter.
1Adserversolutions
1Affiliate Software Java
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname a...Show more
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to logon_process.jsp. NOTE: some of these details are obtained from third party information.Show less