← Back
CWE-89

20,591 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,591)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phparcadescript
1Phparcadescript
Apr 23, 2026
Aug 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a browse action.
1Zeeways
1Zeejobsite
Apr 23, 2026
Aug 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in bannerclick.php in ZEEJOBSITE 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
1Kayako
1Supportsuite
Apr 23, 2026
Aug 15, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users to execute arbitrary SQL commands via the customfieldlinkid parameter in a delcflink action.
1Ypninc
1Php Realty
Apr 23, 2026
Aug 14, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in dpage.php in YPN PHP Realty allows remote attackers to execute arbitrary SQL commands via the docID parameter.
1Pozscripts
1Tubeguru Video Sharing Script
Apr 23, 2026
Aug 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ugroups.php in PozScripts TubeGuru Video Sharing Script allows remote attackers to execute arbitrary SQL commands via the UID parameter.
1Pozscripts
1Classified Ads
Apr 23, 2026
Aug 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in browsecats.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3672.
1Pozscripts
1Classified Ads
Apr 23, 2026
Aug 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in showcategory.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3673. NOTE: the provenance of...Show more
SQL injection vulnerability in showcategory.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3673. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Articlefriendly
1Article Friendly
Apr 23, 2026
Aug 13, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in authordetail.php in Article Friendly Pro allows remote attackers to execute arbitrary SQL commands via the autid parameter.
1Zeescripts
1Zeereviews
Apr 23, 2026
Aug 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in comments.php in ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script (aka ZeeReviews) allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
1Articlefriendly
1Article Friendly
Apr 23, 2026
Aug 13, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in categorydetail.php in Article Friendly Standard allows remote attackers to execute arbitrary SQL commands via the Cat parameter.
1Zeescripts
1Zeebuddy
Apr 23, 2026
Aug 12, 2008
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
1Vacation Rentals
1Vacation Rental Script
Apr 23, 2026
Aug 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Vacation Rental Script 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a sections action.
1Quicksilver Forums
1Quicksilver Forums
Apr 23, 2026
Aug 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Quicksilver Forums 1.4.1 allows remote attackers to execute arbitrary SQL commands via the forums array parameter in a search action.
1Openimpro
1Openimpro
Apr 23, 2026
Aug 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in image.php in OpenImpro 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Psi Labs
1Psipuss
Apr 23, 2026
Aug 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in psipuss 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the Cid parameter to categories.php or (2) the Username parameter to login.php.
1Magicscripts
2E Store Kit 1
E Store Kit 2
Apr 23, 2026
Aug 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in viewdetails.php in MagicScripts E-Store Kit-1, E-Store Kit-2, E-Store Kit-1 Pro PayPal Edition, and E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary SQL commands vi...Show more
SQL injection vulnerability in viewdetails.php in MagicScripts E-Store Kit-1, E-Store Kit-2, E-Store Kit-1 Pro PayPal Edition, and E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary SQL commands via the pid parameter.Show less
121degrees
1Symphony
Apr 23, 2026
Aug 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to...Show more
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to index.php.Show less
1Egi Zaberl
1E.z. Poll
Apr 23, 2026
Aug 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in admin/login.asp in E. Z. Poll 2 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password parameters. NOTE: the provenance of this informati...Show more
Multiple SQL injection vulnerabilities in admin/login.asp in E. Z. Poll 2 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Phsblog
1Phsblog
Apr 23, 2026
Aug 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to comments.php, (2) cid parameter to index.php, and the (3) urltitle parameter t...Show more
Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to comments.php, (2) cid parameter to index.php, and the (3) urltitle parameter to entries.php.Show less
1Joomla
1Com Ezstore
Apr 23, 2026
Aug 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.