← Back
CWE-89

20,597 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,597)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Uniwin
1Ecart Professional
Apr 23, 2026
Oct 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Uniwin eCart Professional 2.0.17 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to (1) search.asp and (2) cartUtil.asp.
1Dxproscripts
1Dxshopcart
Apr 23, 2026
Oct 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in product_detail.php in DXShopCart 4.30mc allows remote attackers to execute arbitrary SQL commands via the pid parameter.
1Quidascript
1Faq Management Script
Apr 23, 2026
Oct 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in QuidaScript FAQ Management Script allows remote attackers to execute arbitrary SQL commands via the catid parameter.
1Tufat
1Mycard
Apr 23, 2026
Oct 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Aves
1Rpg Board
Apr 23, 2026
Oct 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in RPG.Board 0.8 Beta2 and earlier allows remote attackers to execute arbitrary SQL commands via the showtopic parameter.
1Pressography
1Wp Comment Remix Plugin
Apr 23, 2026
Oct 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the p parameter.
1Zeeways
1Zeelyrics
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in bannerclick.php in ZEELYRICS 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
1Scriptdemo
1Php Lance
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
1Jpad Project
1Jpad
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.
1212cafe
1212cafeboard
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands via the qID parameter.
1Joovili
1Joovili
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.blog.php, (2) view.event.php, (3) view...Show more
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.blog.php, (2) view.event.php, (3) view.group.php, (4) view.music.php, (5) view.picture.php, and (6) view.video.php.Show less
1Pilot Group
1Etraining
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Vbulletin
1Vbgooglemap
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php an...Show more
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php.Show less
1Phponlinedatingsoftware
1Myphpdating
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in success_story.php in php Online Dating Software MyPHPDating allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Bosdev
1Bosnews
Apr 23, 2026
Oct 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter.
1Liberiacms
1Liberia Cms
Apr 23, 2026
Oct 22, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in admin.php in Libera CMS 1.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the libera_staff_user cookie parameter, a different vector tha...Show more
SQL injection vulnerability in admin.php in Libera CMS 1.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the libera_staff_user cookie parameter, a different vector than CVE-2008-4700. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Liberiacms
1Liberia Cms
Apr 23, 2026
Oct 22, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in admin.php in Libera CMS 1.12 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the libera_staff_pass cookie parameter.
1Phpcounter
1Phpcounter
Apr 23, 2026
Oct 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in PHPcounter 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter.
1Conkurent
1Real Estate
Apr 23, 2026
Oct 22, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in browse mode.
1Deeserver
1Ultimate Webboard
Apr 23, 2026
Oct 22, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL commands via the Category parameter.