← Back
CWE-89

20,597 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,597)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Maran
1Php Shop
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.
1Maran
1Php Shop
Apr 23, 2026
Nov 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2008-4880.
1Cce Interact
1Interact
Apr 23, 2026
Nov 3, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in spaces/emailuser.php in Interact 2.4.1 allows remote attackers to execute arbitrary SQL commands via the email_user_key parameter.
1Mywebcards
1Webcards
Apr 23, 2026
Nov 1, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in admin.php in WebCards 1.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: some of these details are obtained fro...Show more
SQL injection vulnerability in admin.php in WebCards 1.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: some of these details are obtained from third party information.Show less
1Ibm
1Lotus Connections
Apr 23, 2026
Oct 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sortField parameter to unspecified components. NOTE: the provenance of th...Show more
Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sortField parameter to unspecified components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Nukedgallery
1Gallery
Apr 23, 2026
Oct 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid parameter in a showalbum action to index.php. NOTE: some of these details are obta...Show more
SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid parameter in a showalbum action to index.php. NOTE: some of these details are obtained from third party information. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.Show less
1E107
1Easyshop Plugin
Apr 23, 2026
Oct 29, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
1E107
1Alternate Profiles Plugin
Apr 23, 2026
Oct 29, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Aiocp
1Aiocp
Apr 23, 2026
Oct 29, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.
1Dream4
1Koobi Cms
Apr 23, 2026
Oct 29, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL commands via the galid parameter in a showimages action.
1Joomla
1Com Lms
Apr 23, 2026
Oct 29, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Showroom Joomlearn LMS (com_lms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showTests task.
1Questwork
1Questcms
Apr 23, 2026
Oct 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in main/main.php in QuestCMS allows remote attackers to execute arbitrary SQL commands via the obj parameter.
1Tlm Cms
1Tlm Cms
Apr 23, 2026
Oct 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in TLM CMS 3.1 allows remote attackers to execute arbitrary SQL commands via the nom parameter to a-b-membres.php. NOTE: the goodies.php vector is already covered by CVE-2007-4808. NOTE: the...Show more
SQL injection vulnerability in TLM CMS 3.1 allows remote attackers to execute arbitrary SQL commands via the nom parameter to a-b-membres.php. NOTE: the goodies.php vector is already covered by CVE-2007-4808. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1O2php
1Oxygen Bulletin Board
Apr 23, 2026
Oct 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in member.php in Oxygen Bulletin Board 1.1.3 allows remote attackers to execute arbitrary SQL commands via the member parameter. NOTE: the provenance of this information is unknown; the detai...Show more
SQL injection vulnerability in member.php in Oxygen Bulletin Board 1.1.3 allows remote attackers to execute arbitrary SQL commands via the member parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Oscommerce
1Poll Booth
Apr 23, 2026
Oct 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results operation. NOTE: this issue was disclosed...Show more
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results operation. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.Show less
1Graphiks
1Myforum
Apr 23, 2026
Oct 28, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in lecture.php in Graphiks MyForum 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Php Daily
1Php Daily
Apr 23, 2026
Oct 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in PHP-Daily allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) add_postit.php (b) delete.php, and (c) mod_prest_date.php; and the (2) prev par...Show more
Multiple SQL injection vulnerabilities in PHP-Daily allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) add_postit.php (b) delete.php, and (c) mod_prest_date.php; and the (2) prev parameter to (d) prest_detail.php.Show less
1Pozscripts
1Classified Auctions Script
Apr 23, 2026
Oct 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in gotourl.php in PozScripts Classified Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Scripts For Sites
1Ez Forum
Apr 23, 2026
Oct 27, 2008
N/A· v4
N/A· v3
5.8 MEDIUM· v2
SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.
1Aj Square Inc
1Rss Reader
Apr 23, 2026
Oct 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in EditUrl.php in AJ Square RSS Reader allows remote attackers to execute arbitrary SQL commands via the url parameter.