← Back
CWE-89

20,589 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,589)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Greatclone
1Youtuber Clone
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands via the UID parameter.
1Willo
1Trio
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in browse.php in TriO 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Fipsasp
1Fipscms Light
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the r parameter, a different vector than CVE-2006-6115 and CVE-2007-2561.
1Icebb
1Icebb
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrary SQL commands via the username parameter in a members action to index.php, related to an incorrect...Show more
SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrary SQL commands via the username parameter in a members action to index.php, related to an incorrect protection mechanism in the clean_string function in includes/functions.php.Show less
1Siteadmin
1Cms
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in line2.php in SiteAdmin allows remote attackers to execute arbitrary SQL commands via the art parameter.
1Greatclone
1Auction Platinum
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.
1Ecshop
1Epshop
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI.
1Phplinkat
1Phplinkat
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in showcat.php in phpLinkat 0.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
1Mojoscripts
1Mojopersonals
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in mojoClassified.cgi in MojoPersonals allows remote attackers to execute arbitrary SQL commands via the cat parameter.
1Infomining
1Bookmine
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in events.cfm in BookMine allows remote attackers to execute arbitrary SQL commands via the events_id parameter.
1Easy Script
1Def Blog
Apr 23, 2026
Jul 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Def-Blog 1.0.3 allow remote attackers to execute arbitrary SQL commands via the article parameter to (1) comaddok.php and (2) comlook.php.
1Phpfootball
1Phpfootball
Apr 23, 2026
Jul 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the dbtable parameter.
1Alstrasoft
1Video Share Enterprise
Apr 23, 2026
Jul 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute arbitrary SQL commands via the UID parameter, a different vector than CVE-2007-4086.
1Mojoscripts
1Mojoauto
Apr 23, 2026
Jul 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via the cat_a parameter in a browse action.
1Mojoscripts
1Mojoclassifieds
Apr 23, 2026
Jul 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in mojoClassified.cgi in MojoClassifieds 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_a parameter.
1Fizzmedia Negativekarma
1Fizzmedia
Apr 23, 2026
Jul 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands via the mid parameter.
1Brandon Tallent
1Phptest
Apr 23, 2026
Jul 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in picture.php in phpTest 0.6.3 allows remote attackers to execute arbitrary SQL commands via the image_id parameter.
1Gregarius
1Gregarius
Apr 23, 2026
Jul 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the rsargs array parameter in an __exp__getFeedContent action.
1Greatclone
1Getacoder Clone
Apr 23, 2026
Jul 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search_form.php in Getacoder Clone allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter.
1Emc
1Centera Universal Access
Apr 23, 2026
Jul 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the CUA Login Module in EMC Centera Universal Access (CUA) 4.0_4735.p4 allows remote attackers to execute arbitrary SQL commands via the user (user name) field.