← Back
CWE-89

20,597 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,597)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Shahrood
1Shahrood
Apr 23, 2026
Nov 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ndetail.php in Shahrood allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Phpx
1Phpx
Apr 23, 2026
Nov 10, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via uppercase characters in the news_id parameter.
1Ec Cube
1Ec Cube
Apr 23, 2026
Nov 6, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in LOCKON CO.,LTD. EC-CUBE 2.3.0 and earlier, 1.4.7 and earlier, and 1.5.0-beta2 and earlier; and Community Edition 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands...Show more
SQL injection vulnerability in LOCKON CO.,LTD. EC-CUBE 2.3.0 and earlier, 1.4.7 and earlier, and 1.5.0-beta2 and earlier; and Community Edition 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the parameter.Show less
1W1n78
1Lyrics
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary SQL commands via the l_id parameter. NOTE: some of these details are obtained...Show more
SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary SQL commands via the l_id parameter. NOTE: some of these details are obtained from third party information.Show less
1Typosphere
1Typo
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in the "Manage pages" feature (admin/pages) in Typo 5.1.3 and earlier allows remote authenticated users with "blog publisher" rights to execute arbitrary SQL commands via the search[published_...Show more
SQL injection vulnerability in the "Manage pages" feature (admin/pages) in Typo 5.1.3 and earlier allows remote authenticated users with "blog publisher" rights to execute arbitrary SQL commands via the search[published_at] parameter.Show less
1Scripts Frenzy
1Article Publisher Pro
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.
1Scripts Frenzy
1Article Publisher Pro
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.
1Yourfreeworld
1Classifieds Blaster Script
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Logz
1Logz
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in fichiers/add_url.php in Logz podcast CMS 1.3.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the art parameter.
1Yourfreeworld
1Downline Builder Script
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Rs Maxsoft
1Fotogalerie
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute arbitrary SQL commands via the fotoID parameter. NOTE: this issue was disclosed by an unreliable re...Show more
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute arbitrary SQL commands via the fotoID parameter. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.Show less
11st News
14 Professional
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in products.php in 1st News 4 Professional (PR 1) allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Dev!l's
1Clanportal
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in deV!L'z Clanportal (DZCP) 1.4.9.6 and earlier allows remote attackers to execute arbitrary SQL commands via the users parameter in an addbuddy operation in a buddys action.
1Netrisk
1Netrisk
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in NetRisk 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) profile page (profile.php) or (2) game page (game.php). NOTE: s...Show more
SQL injection vulnerability in index.php in NetRisk 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) profile page (profile.php) or (2) game page (game.php). NOTE: some of these details are obtained from third party information.Show less
1Yourfreeworld
1Shopping Cart Script
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c parameter.
1Yourfreeworld
1Scrolling Text Ads Script
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Yourfreeworld
1Classifieds Hosting Script
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Yourfreeworld
1Blog Blaster Script
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Yourfreeworld
1Autoresponder Hosting Script
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Yourfreeworld
1Reminder Service Script
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitrary SQL commands via the id parameter.