← Back
CWE-89

20,595 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,595)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Galerie
1Galerie
Apr 23, 2026
Oct 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in galerie.php in Galerie 3.2 allows remote attackers to execute arbitrary SQL commands via the pic parameter.
1Phpautos
1Phpautos
Apr 23, 2026
Oct 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
1Built2go
1Real Estate Listings
Apr 23, 2026
Oct 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.
1Select Development Solutions
1Php Realtor
Apr 23, 2026
Oct 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_cat.php in PHP Realtor 1.5 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter.
1Select Development Solutions
1Php Auto Dealer
Apr 23, 2026
Oct 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_cat.php in PHP Auto Dealer 2.7 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter.
1Torrenttrader
1Torrenttrader
Apr 23, 2026
Oct 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Yourownbux
1Yourownbux
Apr 23, 2026
Oct 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands via the usNick cookie.
1Atarone
1Atarone
Apr 23, 2026
Oct 8, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in ap-save.php in Atarone CMS 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) site_name, (2) email, (3) theme_chosen, (4) hp, (5) c_meta, (6) id, and (7) c_js param...Show more
SQL injection vulnerability in ap-save.php in Atarone CMS 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) site_name, (2) email, (3) theme_chosen, (4) hp, (5) c_meta, (6) id, and (7) c_js parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1V Webmail
1V Webmail
Apr 23, 2026
Oct 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in V-webmail 1.5.0 might allow remote attackers to execute arbitrary SQL commands via the username parameter.
1Vastal I Tech
1Freelance Zone
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the coder_id parameter.
1Vastal I Tech
1Share Zone
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_news.php in Vastal I-Tech Share Zone allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Vastal I Tech
1Toner Cart
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Vastal I Tech
1Cosmetics Zone
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_products_cat.php in Vastal I-Tech Cosmetics Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
1Vastal I Tech
1Dvd Zone
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_mags.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
1Vastal I Tech
1Mag Zone
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_mags.php in Vastal I-Tech Mag Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
1Vastal I Tech
1Jobs Zone
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_news.php in Vastal I-Tech Jobs Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
1Vastal I Tech
1Visa Zone
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_news.php in Vastal I-Tech Visa Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
1Vastal I Tech
1Dating Zone
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in advanced_search_results.php in Vastal I-Tech Dating Zone, possibly 0.9.9, allows remote attackers to execute arbitrary SQL commands via the fage parameter.
1Vastal I Tech
1Mmorpg Zone
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in game.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the game_id parameter.
1Extrovert Software
1Thyme
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in pick_users.php in the groups module in eXtrovert Thyme 1.3 allows remote attackers to execute arbitrary SQL commands via the uname_search parameter. NOTE: some of these details are obtaine...Show more
SQL injection vulnerability in pick_users.php in the groups module in eXtrovert Thyme 1.3 allows remote attackers to execute arbitrary SQL commands via the uname_search parameter. NOTE: some of these details are obtained from third party information.Show less