← Back
CWE-89

20,593 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,593)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Myphpnuke
1Myphpnuke
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the sid parameter.
1Source Workshop
1Reciprocal Links Manager
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Reciprocal Links Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.
1Myiosoft
1Easyclassifields
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in staticpages/easyclassifields/index.php in MyioSoft EasyClassifields 3.0 allows remote attackers to execute arbitrary SQL commands via the go parameter in a browse action.
1Brim Project
1Brim
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
SQL injection vulnerability in the Tasks plugin in Brim 2.0.0, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via an arbitrary field in a search action to index.php...Show more
SQL injection vulnerability in the Tasks plugin in Brim 2.0.0, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via an arbitrary field in a search action to index.php.Show less
1Stash
1Stash
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username parameter to admin/library/authenticate.php and the (2) downlo...Show more
SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username parameter to admin/library/authenticate.php and the (2) download parameter to downloadmp3.php. NOTE: some of these details are obtained from third party information.Show less
2Ledgersmb
Sql Ledger
2Ledgersmb
Sql Ledger
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified...Show more
SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.Show less
1Zanfi Solutions
1Autodealers Cms Autonline
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
1Zanfi Solutions
1Autodealers Cms Autonline
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a DBpAGE action.
1Phsdev
1Phsblog
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter in a pickup action or (2) the sql_cid parameter, different vectors tha...Show more
Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter in a pickup action or (2) the sql_cid parameter, different vectors than CVE-2008-3588.Show less
1Texmedia
1Million Pixel Script
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in tops_top.php in Million Pixel Ad Script (Million Pixel Script) allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.
1Kolifa
1Download Script
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in indir.php in Kolifa.net Download Script 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Elitecms
1Elitecms
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in eliteCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
1Aj Square
1Aj Hyip
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in article/readarticle.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the artid parameter.
1Aj Square
1Aj Hyip
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in AJ Square AJ HYIP Acme allow remote attackers to execute arbitrary SQL commands via the artid parameter to (1) acme/article/comment.php and (2) prime/article/comment.php.
1Spice Classifieds
1Spice Classifieds
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Spice Classifieds allows remote attackers to execute arbitrary SQL commands via the cat_path parameter.
1Mybb
1Mybb
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.4.1 allows remote attackers to execute arbitrary SQL commands via a certain editor field.
1Masir Camp
1E Shop Module
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Masir Camp E-Shop Module 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ordercode parameter in a veiworderstatus page.
1Alstrasoft
1Forum Pay Per Post Exchange
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showcat action.
1Vastal
1Shaadi Zone
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in keyword_search_action.php in Vastal I-Tech Shaadi Zone 1.0.9 allows remote attackers to execute arbitrary SQL commands via the tage parameter.
1Editeurscripts Esfaq
12.0
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via the idcat parameter.