← Back
CWE-89

20,607 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cfmsource
1Cf Auction
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in forummessages.cfm in CFMSource CF_Auction allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.
1Cfmsource
1Cfmblog
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.
1Cfshopkart
1Cf Shopkart
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.cfm in CF Shopkart 5.2.2 allows remote attackers to execute arbitrary SQL commands via the Category parameter in a ViewCategory action.
1Cfmsource
1Cf Calendar
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in calendarevent.cfm in CF_Calendar allows remote attackers to execute arbitrary SQL commands via the calid parameter.
1Phpbb
1Tag Board
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in tag_board.php in the Tag Board module 4.0 and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.
1Manzovi
1Proquiz
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.
1Butterflymedia
1Butterfly Organizer
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name.
1W3matter
1Revsense
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party inform...Show more
SQL injection vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information.Show less
1W3matter
1Askpert
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information...Show more
SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information.Show less
1Xt Commerce
1Xt Commerce
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in xt:Commerce before 3.0.4 Sp2.1, when magic_quotes_gpc is enabled and the SEO URLs are activated, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Toursmanager
1Tours Manager
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in tourview.php in ToursManager allows remote attackers to execute arbitrary SQL commands via the tourid parameter.
1Prezmo
1Small Shoutbox
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.
1Toursmanager
1Tours Manager
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cityview.php in Tours Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the cityid parameter.
1Activewebsoftwares
1Active Newsletter
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the passw...Show more
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password field), to (a) Subscriber.asp or (b) start.asp. NOTE: some of these details are obtained from third party information.Show less
1Businessvein
1Php Tv Portal
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in PHP TV Portal 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the mid parameter.
11scripts
1Z1exchange
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via the site parameter.
1Ortus.nirn
1Cms Ortus
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the city parameter in a users_edit_pub action to index....Show more
SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the city parameter in a users_edit_pub action to index.php.Show less
1Bluocms
1Bluo Cms
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Bluo CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Rakhisoftware
1Rakhisoftware Shopping Cart
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategory_id parameter.
1Drupal
1User Karma Module
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote authenticated administrators to execute arbitrary SQL commands via (1) a...Show more
Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote authenticated administrators to execute arbitrary SQL commands via (1) a content type or (2) a voting API value.Show less