← Back
CWE-89

20,600 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,600)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Aj Square
1Aj Auction
Apr 23, 2026
Jan 28, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in sellers_othersitem.php in AJ Auction Pro Platinum 2 allows remote attackers to execute arbitrary SQL commands via the seller_id parameter.
1Drupal
1Ajax Checklist
Apr 23, 2026
Jan 28, 2009
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allow remote authenticated users, with "update ajax checklists" permissions, to execut...Show more
Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allow remote authenticated users, with "update ajax checklists" permissions, to execute arbitrary SQL commands via a save operation, related to the (1) nid, (2) qid, and (3) state parameters.Show less
1Jetik
1Jetik Emlak Sistem A
Apr 23, 2026
Jan 28, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL commands via the KayitNo parameter to (1) diger.php and (2) sayfalar.php.
1Jadu
1Jadu Cms For Government
Apr 23, 2026
Jan 28, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in scripts/recruit_details.php in Jadu CMS for Government allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Php Nuke
1Downloads Module
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
4.6 MEDIUM· v2
SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.
1Groonesworld
1Glinks
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
1Clicktech
1Clickauction
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters. NOTE: some of these details are obtained from...Show more
SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information.Show less
1Gempar
1Script Toko Online
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
1Itlpoll
1Itpoll
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id pa...Show more
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.Show less
1Wazzum
1Wazzum Dating Software
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the userid parameter.
1Shop Inet
1Shop Inet
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.
1Keep Toolkit
1Keep Toolkit
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in lib/patUser.php in KEEP Toolkit before 2.5.1 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password.
1Flaxweb
1Flax Article Manager
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
1Warhound
1Walking Club
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
1Pardalcms
1Pardalcms
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Ocean12 Technologies
1Mailing List Manager
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary SQL commands via the Email parameter to (1) default.asp and (2) s_edit.asp.
1Preprojects
1Php Jobwebsite Pro
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.
1Activewebsoftwares
1Active Price Comparison
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. NOTE: the provenance of this information is unknown; the detail...Show more
SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Activewebsoftwares
1Active Price Comparison
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.
1Activewebsoftwares
1Active Web Mail
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.