← Back
CWE-89

20,600 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,600)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Domainsellerpro
1Domain Seller Pro
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Domain Seller Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1V3chat
1V3 Chat Profiles Dating Script
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.
1Zeeways
1Zeematri
Apr 23, 2026
Dec 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in bannerclick.php in ZeeMatri 3.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
1Cfagcms
1Cfagcms
Apr 23, 2026
Dec 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in right.php in Cant Find A Gaming CMS (CFAGCMS) 1.0 Beta 1 allows remote attackers to execute arbitrary SQL commands via the title parameter.
1Flds Script
1Flds
Apr 23, 2026
Dec 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in lpro.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Flds Script
1Flds
Apr 23, 2026
Dec 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in report.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the linkid parameter.
1Cadenix
1Cadenix
Apr 23, 2026
Dec 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CadeNix allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Apertoblog
1Apertoblog
Apr 23, 2026
Dec 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in categories.php in Aperto Blog 0.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Aspsiteware
1Homebuilder
Apr 23, 2026
Dec 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to (a) type.asp and (b) type2.asp and the (2) iPro parame...Show more
Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to (a) type.asp and (b) type2.asp and the (2) iPro parameter to (c) detail.asp.Show less
1Aspsiteware
1Realtylistings
Apr 23, 2026
Dec 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro parameter to detail.asp.
1Sirium
1Am Events Module
Apr 23, 2026
Dec 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Gazatem
1Gnews Publisher
Apr 23, 2026
Dec 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in authors.asp in gNews Publisher allows remote attackers to execute arbitrary SQL commands via the authorID parameter.
1Fascript
1Faupload
Apr 23, 2026
Dec 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in download.php in Farsi Script Faupload allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Alstrasoft
1Web Email Script Enterprise
Apr 23, 2026
Dec 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a directory action.
1Pligg
1Pligg Cms
Apr 23, 2026
Dec 26, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQL commands via the url parameter.
1Nodstrum
1Mysql Calendar
Apr 23, 2026
Dec 26, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the username parameter.
1Php Fusion
1Team Impact Ti Blog System Module
Apr 23, 2026
Dec 26, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Netcat
1Netcat
Apr 23, 2026
Dec 26, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the query string.
1Stormboards Aaronnemisis
1Stormboards
Apr 23, 2026
Dec 26, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in thread.php in stormBoards 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Aspindir
1Iltaweb Alisveris Sistemi
Apr 23, 2026
Dec 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in urunler.asp in Iltaweb Alisveris Sistemi allows remote attackers to execute arbitrary SQL commands via the catno parameter.