← Back
CWE-89

20,598 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,598)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Clanlite
1Clanlite
Apr 23, 2026
Nov 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary SQL commands via the link parameter.
1Aj Square
1Aj Article
Apr 23, 2026
Nov 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a search detail action.
1Aj Square
1Aj Auction
Apr 23, 2026
Nov 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the item_id parameter.
1Joomla
1Com Datsogallery
Apr 23, 2026
Nov 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
1Joomla
1Com Xewebtv
Apr 23, 2026
Nov 21, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Xe webtv (com_xewebtv) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.
1Vizzed
1Acmlmboard
Apr 23, 2026
Nov 21, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in memberlist.php in Acmlmboard 1.A2 allows remote attackers to execute arbitrary SQL commands via the pow parameter.
1Php Fusion
1Php Fusion
Apr 23, 2026
Nov 21, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a detail_adverts action.
1Php Fusion
1The Kroax Module
Apr 23, 2026
Nov 21, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the category parameter.
1Sebrac
1Sebraccms
Apr 23, 2026
Nov 21, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands via (1) the recid parameter to cms/form/read.php, (2) the uname parameter to cms/index.php, and oth...Show more
Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands via (1) the recid parameter to cms/form/read.php, (2) the uname parameter to cms/index.php, and other unspecified vectors.Show less
1Softvisions Software
1Online Booking Manager
Apr 23, 2026
Nov 21, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in checkavail.php in SoftVisions Software Online Booking Manager (obm) 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Philboard
1Philboard
Apr 23, 2026
Nov 21, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in forum.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: this might overlap CVE-2008-2334, CVE-2008-1939, CVE-2...Show more
SQL injection vulnerability in forum.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: this might overlap CVE-2008-2334, CVE-2008-1939, CVE-2007-2641, or CVE-2007-0920.Show less
1Seportal
1Seportal
Apr 23, 2026
Nov 21, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) poll_id parameter to poll.php and the (2) sp_id parameter to staticpages.php.
1Eshop100
1Eshop100
Apr 23, 2026
Nov 21, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in eSHOP100 allows remote attackers to execute arbitrary SQL commands via the SUB parameter.
1Easysitenetwork
1Jokes Complete Website
Apr 23, 2026
Nov 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in joke.php in Jokes Complete Website 2.1.3 allows remote attackers to execute arbitrary SQL commands via the jokeid parameter.
1Easysitenetwork
1Cheats Complete Website
Apr 23, 2026
Nov 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
1Easysitenetwork
1Drinks Complete Website
Apr 23, 2026
Nov 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in drinks/drink.php in Drinks Complete Website 2.1.0 allows remote attackers to execute arbitrary SQL commands via the drinkid parameter.
1Easysitenetwork
1Tips Complete Website
Apr 23, 2026
Nov 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in tip.php in Tips Complete Website 1.2.0 allows remote attackers to execute arbitrary SQL commands via the tipid parameter.
1Easysitenetwork
1Riddles Website
Apr 23, 2026
Nov 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in riddle.php in Riddles Website 1.2.1 allows remote attackers to execute arbitrary SQL commands via the riddleid parameter.
1Eticket
1Eticket
Apr 23, 2026
Nov 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in eTicket 1.5.7 allow remote attackers to execute arbitrary SQL commands via the pri parameter to (1) index.php, (2) open.php, (3) open_raw.php, and (4) newticket.php.
1Theratstudios
1The Rat Cms
Apr 23, 2026
Nov 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewarticle.php and (2) viewarticle2.php.