← Back
CWE-89

20,595 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,595)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1E Php Scripts
1B2b Trading Marketplace Script
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in listings.php in E-Php B2B Trading Marketplace Script allows remote attackers to execute arbitrary SQL commands via the cid parameter in a product action.
1Memht
1Memht Portal
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in inc/inc_statistics.php in MemHT Portal 3.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a stats_res cookie to index.php.
1Bblog
1Wbblog
Apr 23, 2026
Oct 3, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in bblog_plugins/builtin.help.php in bBlog 0.7.6 allows remote attackers to execute arbitrary SQL commands via the mod parameter.
1Rmsoft
1Minishop Module
Apr 23, 2026
Oct 3, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops might allow remote attackers to execute arbitrary SQL commands via the itemsxpag parameter.
1Icebb
1Icebb
Apr 23, 2026
Oct 3, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in IceBB 1.0-rc9.3 and earlier allows remote attackers to execute arbitrary SQL commands via the skin parameter, probably related to an incorrect protection mechanism in the clean...Show more
SQL injection vulnerability in index.php in IceBB 1.0-rc9.3 and earlier allows remote attackers to execute arbitrary SQL commands via the skin parameter, probably related to an incorrect protection mechanism in the clean_string function in includes/functions.php.Show less
1Ovidentia
1Ovidentia
Apr 23, 2026
Oct 3, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the item parameter in a contact modify action.
1Mr. Cgi Guy
1Hot Links Sql Php
Apr 23, 2026
Oct 1, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter.
1Mr. Cgi Guy
1Hot Links Sql Php
Apr 23, 2026
Oct 1, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Creative Mind
1Creator Cms
Apr 23, 2026
Oct 1, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the sideid parameter.
1Livetvscript
1Live Tv Script
Apr 23, 2026
Oct 1, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Live TV Script allows remote attackers to execute arbitrary SQL commands via the mid parameter.
1Availscript
1Availscript Classmate Script
Apr 23, 2026
Oct 1, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in viewprofile.php in Availscript Classmate Script allows remote attackers to execute arbitrary SQL commands via the p parameter.
1Cmsbuzz
1Cms Buzz
Apr 23, 2026
Oct 1, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CMS Buzz allows remote attackers to execute arbitrary SQL commands via the id parameter in a playgame action.
1Availscript
1Availscript Jobs Portal Script
Apr 23, 2026
Oct 1, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in job_seeker/applynow.php in AvailScript Job Portal Script allows remote attackers to execute arbitrary SQL commands via the jid parameter.
1Availscript
1Availscript Article Script
Apr 23, 2026
Oct 1, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in articles.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL commands via the aIDS parameter.
1Availscript
1Availscript Photo Album
Apr 23, 2026
Oct 1, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in pics.php in Availscript Photo Album allows remote attackers to execute arbitrary SQL commands via the sid parameter.
1Parsagostar
1Parsaweb Cms
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.aspx in ParsaGostar ParsaWeb CMS allows remote attackers to execute arbitrary SQL commands via the (1) id parameter in the "page" page and (2) txtSearch parameter in the "Search" pa...Show more
SQL injection vulnerability in default.aspx in ParsaGostar ParsaWeb CMS allows remote attackers to execute arbitrary SQL commands via the (1) id parameter in the "page" page and (2) txtSearch parameter in the "Search" page.Show less
1Powie
1Plink
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in linkto.php in Powie pLink 2.07 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Kasseler Cms
1Kasseler Cms
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Kasseler CMS 1.1.0 and 1.2.0 allow remote attackers to execute arbitrary SQL commands via (1) the nid parameter to index.php in a View action to the News module; (2) the vid para...Show more
Multiple SQL injection vulnerabilities in Kasseler CMS 1.1.0 and 1.2.0 allow remote attackers to execute arbitrary SQL commands via (1) the nid parameter to index.php in a View action to the News module; (2) the vid parameter to index.php in a Result action to the Voting module; (3) the fid parameter to index.php in a ShowForum action to the Forum module; (4) the tid parameter to index.php in a ShowTopic action to the Forum module; (5) the uname parameter to index.php in a UserInfo action to the Account module; or (6) the module parameter to index.php, probably related to the TopSites module.Show less
1Powie
1Pforum
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Net Art Media
1Iboutique
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the products module in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php.