← Back
CWE-89

20,595 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,595)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linkarity
1Linkarity
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in link.php in Linkarity allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. NOTE: although one component of Linkarity is distributable PHP code, this issue mig...Show more
SQL injection vulnerability in link.php in Linkarity allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. NOTE: although one component of Linkarity is distributable PHP code, this issue might be site-specific. If so, it should not be included in CVE.Show less
1Phpsmartcom
1Phpsmartcom
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in inc/pages/viewprofile.php in phpSmartCom 0.2 allows remote attackers to execute arbitrary SQL commands via the uid parameter in a viewprofile action to index.php.
1Vblogix
1Tutorial Script
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in main.php in vbLOGIX Tutorial Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
1Outshine
1Phportfolio
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in photo.php in PHPortfolio, possibly 1.3, allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Powie
1Pnews
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in newskom.php in Powie pNews 2.03 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
1Webportal
1Webportal Cms
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the aid parameter.
16rbscript
16rbscript
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cat.php in 6rbScript allows remote attackers to execute arbitrary SQL commands via the CatID parameter.
1Vacilanda
1Brilliant Gallery
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in the brilliant_gallery_checklist_save function in the bgchecklist/save script in Brilliant Gallery 5.x and 6.x, a module for Drupal, allows remote authenticated users with "access brilliant_...Show more
SQL injection vulnerability in the brilliant_gallery_checklist_save function in the bgchecklist/save script in Brilliant Gallery 5.x and 6.x, a module for Drupal, allows remote authenticated users with "access brilliant_gallery" permissions to execute arbitrary SQL commands via the (1) nid, (2) qid, (3) state, and possibly (4) user parameters.Show less
1Atomic Photo Album
1Atomic Photo Album
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitrary SQL commands via the apa_album_ID parameter.
1Cannot
1Php Infoboard
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the showjavatopic function in func.php in PHP infoBoard V.7 Plus allows remote attackers to execute arbitrary SQL commands via the idcat parameter to showtopic.php.
1Easyrealtorpro
1Easyrealtorpro
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in site_search.php in EasyRealtorPRO 2008 allows remote attackers to execute arbitrary SQL commands via the (1) item, (2) search_ordermethod, and (3) search_order parameters.
1Rubyonrails
2Rails
Ruby On Rails
Apr 23, 2026
Sep 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveR...Show more
Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.Show less
1Cj
1Ultra Plus
Apr 23, 2026
Sep 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in CJ Ultra Plus 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via an SID cookie.
1Attachmax
1Dolphin
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search.php Attachmax Dolphin 2.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a Search action to index.php. NOTE: some of these det...Show more
SQL injection vulnerability in search.php Attachmax Dolphin 2.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a Search action to index.php. NOTE: some of these details are obtained from third party information.Show less
1Softacid
1Hotel Reservation System
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter.
1Czaries
1Czarnews
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQL commands via a recook cookie.
1Gonafish
1Linkscaffepro
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Gonafish LinksCaffePRO 4.5 allows remote attackers to execute arbitrary SQL commands via the idd parameter in a deadlink action.
1Dieselscripts
1Diesel Joke Site
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-3763.
1Drupal
1Mailhandler
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to composin...Show more
SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to composing queries without using the Drupal database API.Show less
1Addalink
1Addalink
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category_id parameter.