← Back
CWE-89

19,889 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (19,889)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Myphp
1Myphp Forum
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the member.php vector is already covered by CVE-2005-0413.
1Zenphoto
1Zenphoto
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr parameter.
1Netchemia
1Oneschool
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/login.asp in Netchemia oneSCHOOL allows remote attackers to execute arbitrary SQL commands via the txtLoginID parameter.
1Webportal
1Webportal Cms
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in WebPortal CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter.
1Pragmatic Utopia
1Pu Arcade
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in (1) Puarcade.php and (2) PUarcade.html.php in Pragmatic Utopia PU Arcade (com_puarcade) 2.0.3, 2.1.2, and 2.1.3 Beta component for Joomla! allows remote attackers to execute arbitrary SQL...Show more
SQL injection vulnerability in (1) Puarcade.php and (2) PUarcade.html.php in Pragmatic Utopia PU Arcade (com_puarcade) 2.0.3, 2.1.2, and 2.1.3 Beta component for Joomla! allows remote attackers to execute arbitrary SQL commands via the fid parameter to index.php.Show less
1Customcms
1Ccms
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin.php/vars.php in CustomCMS (CCMS) 3.1 Demo allows remote attackers to execute arbitrary SQL commands via the p parameter in the Console page.
1Cmsmadesimple
1Cms Made Simple
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter.
1W Agora
1W Agora
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in w-Agora 4.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.
1Clip Share
1Clipshare
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in uprofile.php in ClipShare allows remote attackers to execute arbitrary SQL commands via the UID parameter.
1Iptbb Team
1Iptbb
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in IPTBB 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewdir action.
1Netbizcity
1Faqmasterflexplus
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in FAQMasterFlexPlus, possibly 1.5 or 1.52, allow remote attackers to execute arbitrary SQL commands via the category_id parameter to faq.php, and unspecified other vectors involvin...Show more
Multiple SQL injection vulnerabilities in FAQMasterFlexPlus, possibly 1.5 or 1.52, allow remote attackers to execute arbitrary SQL commands via the category_id parameter to faq.php, and unspecified other vectors involving additional scripts.Show less
1Zeuscms
1Zeuscms
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in security.php in ZeusCMS 0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.
1Noserub
1Noserub
Apr 23, 2026
Dec 31, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in app/models/identity.php in NoseRub 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username field to the login script.
1Plogger
1Plogger
Apr 23, 2026
Dec 28, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Niclor
1Niclor
Apr 23, 2026
Dec 28, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a sezione page action to index.php.
11024 Cms
11024 Cms
Apr 23, 2026
Dec 28, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/ops/findip/ajax/search.php in 1024 CMS 1.3.1 allows remote attackers to execute arbitrary SQL commands via the ip parameter.
1Wallpaper
1Wallpaper Complete Website
Apr 23, 2026
Dec 28, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter to category.php or (2) the groupid parameter to editadgroup.php.
1Ip Reg
1Ip Reg
Apr 23, 2026
Dec 28, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vlan_id parameter to (1) vlanview.php, (2) vlanedit.php, and (3) vlandel.php; the (4) assetclassgroup_...Show more
Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vlan_id parameter to (1) vlanview.php, (2) vlanedit.php, and (3) vlandel.php; the (4) assetclassgroup_id parameter to assetclassgroupview.php; the (5) subnet_id parameter to nodelist.php; and unspecified other vectors. NOTE: it was later reported that the vlanview.php and vlandel.php vectors are also in 0.4.Show less
1Zeak.net
1Php Zlink
Apr 23, 2026
Dec 28, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in go.php in PHP ZLink 0.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Zsuite
1Zblog
Apr 23, 2026
Dec 28, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the categ parameter in a categ action or (2) the article parameter in an articles action.