← Back
CWE-89

20,607 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adserversolutions
1Banner Exchange Software
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote attackers to execute arbitrary SQL commands via the (1) username (uname parameter) and (2) password (pas...Show more
SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote attackers to execute arbitrary SQL commands via the (1) username (uname parameter) and (2) password (pass parameter). NOTE: some of these details are obtained from third party information.Show less
1Ezonelink
1Multiple Membership Script
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in sitepage.php in Multiple Membership Script 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Socialgroupie
1Social Groupie
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in group_index.php in Social Groupie allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Asp Cms
1Asp Cms
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cha parameter.
1Xpoze
1Xpoze Pro
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via the menu parameter.
1Turnkeyforms
1Local Classifieds
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via the r parameter.
1Turnkeyforms
1Business Survey Pro
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Developiteasy
1Photo Gallery
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id parameter to gallery_p...Show more
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id parameter to gallery_photo.php, and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of these details are obtained from third party information.Show less
1Cms.maury91
1Solarcms
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to indes.php. NOTE: some of these details are obtained from third party...Show more
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to indes.php. NOTE: some of these details are obtained from third party information.Show less
1Typo3
1Tu Clausthal Staff
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the TU-Clausthal Staff (tuc_staff) 0.3.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Weber Ebusiness
1Wes Facilities
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the WEBERkommunal Facilities (wes_facilities) extension 2.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Joomlaapps
1Com Volunteer
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the job_id parameter in a jobshow action to index.php.
1Matthew General
1Rss Simple News
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the pid parameter.
1Simplecustomer
1Simple Customer
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.
1Jaia Interactive
1Mytopix
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the send parameter in a notes action.
1Preproject
1Pre Asp Job Board
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Employee/login.asp in Pre ASP Job Board allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password parameters, as reachable from Employee/emp_login.asp....Show more
SQL injection vulnerability in Employee/login.asp in Pre ASP Job Board allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password parameters, as reachable from Employee/emp_login.asp. NOTE: some of these details are obtained from third party information.Show less
1Butterflymedia
1Butterfly Organizer
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Manzovi
1Proquiz
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter, a different vector than CVE-2008-6312.
1Simplecustomer
1Simple Customer
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in Simple Customer as downloaded on 20081118 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknow...Show more
SQL injection vulnerability in login.php in Simple Customer as downloaded on 20081118 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Cfmsource
1Cf Forum
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.