← Back
CWE-89

20,593 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,593)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ephpscripts
1E Php Cms
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via the es_id parameter.
1Webcms
1Webcms Portal Edition
Apr 23, 2026
Sep 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id_doc parameter. NOTE: the provenance of this information is unknown; the details are...Show more
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id_doc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Webcms
1Webcms Portal Edition
Apr 23, 2026
Sep 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter in a documentos action, a different vector than CVE-2008-3213.
1Downline Goldmine
2Builder
New Addon
Apr 23, 2026
Sep 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and Downline Goldmine Builder allows remote attackers to execute arbitrary SQL commands via the id parame...Show more
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and Downline Goldmine Builder allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.Show less
1Preprojects
1Pre Real Estate Listings
Apr 23, 2026
Sep 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c parameter.
1Asp Indir
1Fot Video Scripti
Apr 23, 2026
Sep 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in izle.asp in FoT Video scripti 1.1 beta allows remote attackers to execute arbitrary SQL commands via the oyun parameter.
1Linkbidscript
1Linkbidscript
Apr 23, 2026
Sep 23, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in Link Bid Script 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) ucat parameter to upgrade.php and the (2) id parameter to linkadmin/edit.php.
1Assetman
1Assetman
Apr 23, 2026
Sep 22, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of crafted order and order_by parameters in...Show more
SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of crafted order and order_by parameters in a search_all action.Show less
1Proarcadescript
1Proarcadescript
Apr 23, 2026
Sep 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the random parameter to the default URI.
1Rfaah
1Cars Vehicles Script
Apr 23, 2026
Sep 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.
1Invision Power Services
1Invision Power Board
Apr 23, 2026
Sep 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in xmlout.php in Invision Power Board (IP.Board or IPB) 2.2.x and 2.3.x allows remote attackers to execute arbitrary SQL commands via the name parameter.
1Iscripts
1Easyindex
Apr 23, 2026
Sep 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commands via the produid parameter.
1Zanfi Solutions
2Jaw Portal
Zanfi Cms Lite
Apr 23, 2026
Sep 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitrary SQL commands via the page (pageid) parameter.
1Vastal
1Phpvid
Apr 23, 2026
Sep 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2007-3610. NOTE: it was later reported t...Show more
SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2007-3610. NOTE: it was later reported that 1.2.3 is also affected.Show less
1Customcms
1Gaming Portal
Apr 23, 2026
Sep 19, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Living E
1Webedition Cms
Apr 23, 2026
Sep 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in living-e webEdition CMS allows remote attackers to execute arbitrary SQL commands via the we_objectID parameter.
1Yourownbux
1Yourownbux
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter.
1Myphpnuke
1Myphpnuke
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the artid parameter.
1Source Workshop
1Web Directory Script
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in Web Directory Script 1.5.3 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.
1Couponscript
1Coupon Script
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in PHP Coupon Script 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an addtocart action, a different vector than CVE-2007-2672.