← Back
CWE-89

20,600 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,600)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Drupal
1Everyblog
Apr 23, 2026
Feb 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Ozsari
1Full Php Emlak Script
Apr 23, 2026
Feb 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in arsaprint.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3942.
1Cafeengine
1Easycafeengine
Apr 23, 2026
Feb 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-4604.
2Debian
Moodle
2Debian Linux
Moodle
Apr 23, 2026
Feb 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers...Show more
SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt.Show less
1Proftpd
1Proftpd
Apr 23, 2026
Feb 12, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2)...Show more
ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.Show less
1Proftpd Project
1Proftpd
Apr 23, 2026
Feb 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) characte...Show more
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql.Show less
1Flexcms
1Flexcms
Apr 23, 2026
Feb 11, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter.
1Ontarioabandonedplaces
1A Better Member Based Asp Photo Gallery
Apr 23, 2026
Feb 11, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
1Rhadrix
1If Cms
Apr 23, 2026
Feb 11, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Socialengine
1Socialengine
Apr 23, 2026
Feb 11, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in profile_comments.php in SocialEngine (SE) 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the comment_secure parameter.
1Pilotgroup
1Pg Job Site Pro
Apr 23, 2026
Feb 11, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in homepage.php in PG Job Site Pro allows remote attackers to execute arbitrary SQL commands via the poll_view_id parameter in a results action.
1Extrosoft
1Com Thyme
Apr 23, 2026
Feb 11, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the EXtrovert Software Thyme (com_thyme) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event parameter to index.php.
1Prozilla
1Hosting Index
Apr 23, 2026
Feb 11, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action, a different vector than CVE-2008-2083.
1Mytipper
1Zogo Shop
Apr 23, 2026
Feb 11, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attackers to execute arbitrary SQL commands via the product parameter.
1Netart Media
1Vlog System
Apr 23, 2026
Feb 11, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in blog.php in NetArt Media Vlog System 1.1 allows remote attackers to execute arbitrary SQL commands via the note parameter.
1Businessspace
1Businessspace
Apr 23, 2026
Feb 11, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the classified page (classified.php) in BusinessSpace 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
1A4desk
1A4desk Flash Event Calendar
Apr 23, 2026
Feb 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in A4Desk PHP Event Calendar allows remote attackers to execute arbitrary SQL commands via the eventid parameter to admin/index.php.
1Ezonescripts
1Link Trader Script
Apr 23, 2026
Feb 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ratelink.php in Link Trader Script allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.
1Ezonescripts
1Adult Banner Exchange Website
Apr 23, 2026
Feb 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter.
1Berlios
1Discussion Forum 2k
Apr 23, 2026
Feb 10, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in Discussion Forums 2k 3.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to (a) RSS1.php and (b) RSS2.php...Show more
Multiple SQL injection vulnerabilities in Discussion Forums 2k 3.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to (a) RSS1.php and (b) RSS2.php in misc/; and the (2) SubID parameter to (c) misc/RSS5.php.Show less