← Back
CWE-89

20,600 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,600)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Constructr
1Constructr Cms
Apr 23, 2026
Jan 6, 2009
N/A· v4
N/A· v3
5.1 MEDIUM· v2
SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the show_pag...Show more
SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the show_page parameter.Show less
1Mypbs
1Mypbs
Apr 23, 2026
Jan 6, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary SQL commands via the seasonID parameter.
1Igamingcms
1Igaming Cms
Apr 23, 2026
Jan 5, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to ind...Show more
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to index.php in a viewarticle action.Show less
1Ephpscripts
1E Shop Shopping Cart
Apr 23, 2026
Jan 5, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search_results.php in E-Php Scripts E-Shop (aka E-Php Shopping Cart) Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Gforge
1Gforge
Apr 23, 2026
Jan 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.
1Edreamers
1Ednews
Apr 23, 2026
Jan 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in eDNews_view.php in eDreamers eDNews 2 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
1Web Scribble Solutions
1Webclassifieds
Apr 23, 2026
Jan 2, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in index.php in Web Scribble Solutions webClassifieds 2005 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) password fields in a sign_in action.
1Ilias
1Ilias
Apr 23, 2026
Jan 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in repository.php in ILIAS 3.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ref_id parameter.
1Phpalumni
1Phpalumni
Apr 23, 2026
Jan 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Spip
1Spip
Apr 23, 2026
Jan 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in inc/rubriques.php in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: some of these deta...Show more
SQL injection vulnerability in inc/rubriques.php in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: some of these details are obtained from third party information.Show less
1Joomla
1Com Paxgallery
Apr 23, 2026
Jan 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the PaxGallery (com_paxgallery) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter in a table action to index.php.
1Deltascripts
1Php Classifieds
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka admin field). NOTE: some of these...Show more
SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka admin field). NOTE: some of these details are obtained from third party information.Show less
1Deltascripts
1Php Classifieds
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the siteid parameter, a different vector than CVE-2006-5828.
1E Topbiz
1Number Links 1 Php Script
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action.
1E Topbiz
1Online Store
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/login.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka username field). NOTE: some of these details are obtained...Show more
SQL injection vulnerability in admin/login.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka username field). NOTE: some of these details are obtained from third party information.Show less
1E Topbiz
1Online Store
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
1Typo3
2Fsmi People
Wir Ber Uns Extension
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Wir ber uns [sic] (fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Cms Poll System Extension
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the CMS Poll system (cms_poll) extension before 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Advcalendar Extension
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the advCalendar extension 0.3.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Eluna Page Comments Extension
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.