← Back
CWE-89

20,607 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mjcreation
1Familyproject
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in index.php in FamilyProject 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the logmbr parameter (aka login field) or (2) the mdpmbr parameter (aka pass or "M...Show more
Multiple SQL injection vulnerabilities in index.php in FamilyProject 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the logmbr parameter (aka login field) or (2) the mdpmbr parameter (aka pass or "Mot de passe" field). NOTE: some of these details are obtained from third party information.Show less
1Craftsilicon
1Banking@home
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Login.asp in Craft Silicon Banking@Home 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginName parameter.
1Frankmancuso
1Bluebird
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in BlueBird Prelease allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.
1Frankmancuso
1Mynews
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in MyNews 0.10 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.
1Frankmancuso
1Auth Php
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in Auth Php 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.
1Miticdjd
1Apoll
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execute arbitrary SQL command via the pass parameter.
1Miticdjd
1Apoll
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execute arbitrary SQL command via the user parameter.
1Sadi Samami
1Multi Languages Webshop Online
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Appstate
1Phpwebsite
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in links.php in Appalachian State University phpWebSite allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action.
1Gigcalendar
1Com Gigcalendar
Apr 23, 2026
Feb 24, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the gigcal _...Show more
Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the gigcal _venues_id parameter in a details action to index.php, which is not properly handled by venuedetails.php, and (2) the gigcal_bands_id parameter in a details action to index.php, which is not properly handled by banddetails.php, different vectors than CVE-2009-0726.Show less
1Maxdev
1My Egallery
Apr 23, 2026
Feb 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php.
1Tony Iha Kazungu
1Taifajobs
Apr 23, 2026
Feb 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in jobdetails.php in taifajobs 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the jobid parameter.
1Gigcalendar
1Com Gigcalendar
Apr 23, 2026
Feb 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the gigcal_gigs_id parameter in a details action to index.php.
1E Topbiz
1Slide Popups
Apr 23, 2026
Feb 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/admin.php in E-topbiz Slide Popups 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
1Infireal
1Saturncms
Apr 23, 2026
Feb 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in lib/user/t_user.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the username parameter to the _userLoggedIn function. NOTE: some of these details are obtaine...Show more
SQL injection vulnerability in lib/user/t_user.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the username parameter to the _userLoggedIn function. NOTE: some of these details are obtained from third party information.Show less
1Infireal
1Saturncms
Apr 23, 2026
Feb 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in lib/url/meta_url.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the URL to the translate function. NOTE: the provenance of this information is unknown; the...Show more
SQL injection vulnerability in lib/url/meta_url.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the URL to the translate function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1E Topbiz
1Admanager
Apr 23, 2026
Feb 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view.php in E-topbiz AdManager 4 allows remote attackers to execute arbitrary SQL commands via the group parameter.
1Ultrastats
1Ultrastats
Apr 23, 2026
Feb 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary SQL commands via the serverid parameter.
1Quadcomm
1Q Shop
Apr 23, 2026
Feb 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in users.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the (1) UserID and (2) Pwd parameters. NOTE: this might be related to...Show more
SQL injection vulnerability in users.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the (1) UserID and (2) Pwd parameters. NOTE: this might be related to CVE-2004-2108.Show less
1Openasp
1Openasp
Apr 23, 2026
Feb 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.asp in Openasp 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idpage parameter in the pages module.