← Back
CWE-89

20,601 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,601)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Newlife Blogger
1Newlife Blogger
Apr 23, 2026
Feb 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and earlier, and possibly 3.3.1, allows remote attackers to execute arbitrary SQL commands via the nlb3 cookie.
1Indexscript
1Indexscript
Apr 23, 2026
Feb 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in sug_cat.php in IndexScript 3.0 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter, a different vector than CVE-2007-4069.
1Jmds
1Com Kbase
Apr 23, 2026
Feb 19, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the KBase (com_kbase) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.
1Easy Script
1Cspartner
Apr 23, 2026
Feb 19, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in gestion.php in CSPartner 0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) pseudo and (2) passe parameters.
14site
14site Cms
Apr 23, 2026
Feb 18, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) password parameters to pcgi/4site.pl, (3) page parameter to print/pri...Show more
Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) password parameters to pcgi/4site.pl, (3) page parameter to print/print.shtml, (4) s and (5) i parameters to portfolio/index.shtml, (6) h parameter to hotel/index.php, (7) id parameter to news/news1.shtml, and the (8) th parameter to faq/index.shtml.Show less
1Php Director
1Php Director
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the searching parameter.
1Formfields
1Adman
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in editCampaign.php in AdMan 1.1.20070907 allows remote authenticated users to execute arbitrary SQL commands via the campaignId parameter.
1Hispah
1Text Links Ads
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idtl parameter in a buy action. NOTE: the provenance of this information is unknown...Show more
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idtl parameter in a buy action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Hispah
1Text Links Ads
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idcat parameter.
1Phpmesfilms
1Phpmesfilms
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in PhpMesFilms 1.0 and 1.8 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1W3b Cms
1Aka W3blabor Cms
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the benutzername parameter (aka...Show more
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the benutzername parameter (aka Username field) in a login action.Show less
1Plxwebdev
1Plx Auto Reminder
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a newar action.
1Jayeshp
1Pixel8 Web Photo Album
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Photo.asp in Jay Patel Pixel8 Web Photo Album 3.0 allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter.
1Sepcity
1Faculty Portal
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in deptdisplay.asp in SepCity Faculty Portal allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: this was originally reported for Lawyer Portal, which does n...Show more
SQL injection vulnerability in deptdisplay.asp in SepCity Faculty Portal allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: this was originally reported for Lawyer Portal, which does not have a deptdisplay.asp file.Show less
1Sepcity
1Shopping Mall
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in shpdetails.asp in SepCity Shopping Mall allows remote attackers to execute arbitrary SQL commands via the ID parameter.
1Sepcity
1Classified Ads
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in classdis.asp in SepCity Classified Ads allows remote attackers to execute arbitrary SQL commands via the ID parameter.
1Joomlaapps
1Com Mdigg
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the mDigg (com_mdigg) component 2.2.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cagtegory parameter in a story_lists action to index.php.
1Raven Worx
1Liveticker
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Live Ticker (com_liveticker) module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a viewticker action to index.php.
1Deluxebb
1Deluxebb
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a delete##### parameter in a Delete action, a different...Show more
SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a delete##### parameter in a Delete action, a different vector than CVE-2005-2989.Show less
1Typo3
1Wec Discussion Forum
Apr 23, 2026
Feb 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.