← Back
CWE-89

20,591 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,591)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pozscripts
1Greencart Php Shopping Cart
Apr 23, 2026
Aug 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) product_desc.php and (2) store_info.php.
1Keld
1Php Mysql News Script
Apr 23, 2026
Aug 10, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
1Qsoft
1K Links
Apr 23, 2026
Aug 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to visit.php, or the PATH_INFO to the default URI under (2) report/, (3) addreview...Show more
Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to visit.php, or the PATH_INFO to the default URI under (2) report/, (3) addreview/, or (4) refer/.Show less
1Plogger
1Plogger
Apr 23, 2026
Aug 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the checked array parameter to plog-download.php in an album action and (2) unspecified p...Show more
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the checked array parameter to plog-download.php in an album action and (2) unspecified parameters to plog-remote.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the activate parameter to admin/plog-themes.php, related to theme_dir settings.Show less
1Powergap
1Shopsystem
Apr 23, 2026
Aug 10, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in s03.php in Powergap Shopsystem, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the ag parameter.
1Haudenschilt
1Battlenet Clan Script
Apr 23, 2026
Aug 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in index.php in Battle.net Clan Script 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) showmember parameter in a members action and the (2) thread paramet...Show more
Multiple SQL injection vulnerabilities in index.php in Battle.net Clan Script 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) showmember parameter in a members action and the (2) thread parameter in a board action. NOTE: vector 1 might be the same as CVE-2008-2522.Show less
1Comsenz
1Discuz
Apr 23, 2026
Aug 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parameter in a search action.
1Php Nuke
1Basis Consultant Book Catalog
Apr 23, 2026
Aug 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to modules.php.
1Php Nuke
1Kleinanzeigen Module
Apr 23, 2026
Aug 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Kleinanzeigen module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a visit action to modules.php.
1Wogan May
1Litenews
Apr 23, 2026
Aug 7, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.
1Polypager
1Polypager
Apr 23, 2026
Aug 6, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands via the nr parameter to the default URI.
1Netshinesoftware
1Com Netinvoice
Apr 23, 2026
Aug 6, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action to index.php. NOTE: some of t...Show more
SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action to index.php. NOTE: some of these details are obtained from third party information.Show less
1Myphp Cms
1Myphp Cms
Apr 23, 2026
Aug 6, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in pages.php in MyPHP CMS 0.3.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
1Aspindir
1Pcshey Portal
Apr 23, 2026
Aug 6, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands via the kid parameter.
1Scripts24
2Ipost
Itgp
Apr 23, 2026
Aug 6, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a report action.
1E Topbiz
1Online Dating
Apr 23, 2026
Aug 6, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in members/mail.php in E-topbiz Online Dating 3 1.0 allows remote authenticated users to execute arbitrary SQL commands via the mail_id parameter in a veiw action.
1Phpx
1Phpx
Apr 23, 2026
Aug 6, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrary SQL commands via a PXL cookie.
1Phpauctions
1Phpauction Gpl Enhanced
Apr 23, 2026
Aug 6, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Estoreaff
1Estoreaff
Apr 23, 2026
Aug 5, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action to index.php.
1Endonesia
2Calendar Module
Endonesia
Apr 23, 2026
Aug 4, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the loc_id parameter in a list_events action to mod.php.