← Back
CWE-89

20,601 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,601)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Preproject
1Php Auto Listings Script
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in moreinfo.php in Pre Projects PHP Auto Listings Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the itemno parameter.
1Mole Group
1Airline Ticket Sale Script
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in info.php in Mole Group Airline Ticket Sale Script allows remote attackers to execute arbitrary SQL commands via the flight parameter. NOTE: the vendor has disputed this issue, stating "cra...Show more
SQL injection vulnerability in info.php in Mole Group Airline Ticket Sale Script allows remote attackers to execute arbitrary SQL commands via the flight parameter. NOTE: the vendor has disputed this issue, stating "crazy hackers and so named Security companies [spread] out such false informations. Such scripts or versions [do not] exist.Show less
1Cafuego
1Simple Document Management System
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the pass parameter.
1Bookingcentre
1Booking System For Hotels Group
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute arbitrary SQL commands via the OfertaID parameter.
1Harlandscripts
1Pro Traffic One
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in poll_results.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Harlandscripts
1Pro Traffic One
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in mypage.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary SQL commands via the trg parameter.
1Openx
1Openx
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in www/delivery/ac.php in OpenX 2.6.1 allows remote attackers to execute arbitrary SQL commands via the bannerid parameter.
1Dream4
1Koobi
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL commands via the img_id parameter in the gallerypic page.
1Vastal
1Software Zone
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
1Supernet
1Supernet Shop
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in SuperNET Shop 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to secure/admin/guncelle.asp, (2) kulad and sifre parameters to se...Show more
Multiple SQL injection vulnerabilities in SuperNET Shop 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to secure/admin/guncelle.asp, (2) kulad and sifre parameters to secure/admin/giris.asp, and (3) username and password to secure/admin/default.asp.Show less
1Jakob Persson
1Cobalt
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in adminler.asp in CoBaLT 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained sol...Show more
SQL injection vulnerability in adminler.asp in CoBaLT 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Jakob Persson
1Cobalt
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) urun.asp, (2) admin/bayi_listele.asp, (3) admin/urun_grup_listele.asp, and (4) admin/urun_li...Show more
SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) urun.asp, (2) admin/bayi_listele.asp, (3) admin/urun_grup_listele.asp, and (4) admin/urun_listele.asp.Show less
1Mybboard
1Custom Pages Plugin
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter.
1Kwsphp
1Galerie Module
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands via the id_gal parameter in a gal action.
1Gforge
1Gforge
Apr 23, 2026
Feb 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly ha...Show more
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.Show less
1Gforge
1Gforge
Apr 23, 2026
Feb 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.
1Gforge
1Gforge
Apr 23, 2026
Feb 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.
1Medialab Karlsruhe
1Ownbiblio
Apr 23, 2026
Feb 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the OwnBiblio (com_ownbiblio) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a catalogue action to index.php.
1Joomla
1Ignitegallery
Apr 23, 2026
Feb 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gallery parameter in a view action to inde...Show more
SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gallery parameter in a view action to index.php.Show less
1Mad4media
1Com Mad4joomla
Apr 23, 2026
Feb 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Mad4Joomla Mailforms (com_mad4joomla) component before 1.1.8.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the jid parameter to index.php.