← Back
CWE-89

19,889 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (19,889)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Softbizscripts
1Ad Management Plus Script
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter.
1Softbizscripts
1Banner Exchange Network Script
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
1Softbizscripts
1Link Directory Script
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter, a related issue to CVE-2007-5449.
1Datecomm
1Social Networking Script
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewcat s action on the forum...Show more
SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewcat s action on the forums page.Show less
1Exo
1Exophpdesk
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in ExoPHPdesk allows remote attackers to execute arbitrary SQL commands via the user parameter in a profile fn action.
1Btiteam
1Btitracker
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in include/functions.php in BtiTracker before 1.4.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Xoops
1Mylinks Module
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in brokenlink.php in the mylinks module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.
1Phpmyadmin
1Phpmyadmin
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter.
1Torrentstrike
1Torrentstrike
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in index.php in TBSource, as used in (1) TBDev and (2) TorrentStrike 0.4, allows remote authenticated users to execute arbitrary SQL commands via the choice parameter. NOTE: some of these det...Show more
SQL injection vulnerability in index.php in TBSource, as used in (1) TBDev and (2) TorrentStrike 0.4, allows remote authenticated users to execute arbitrary SQL commands via the choice parameter. NOTE: some of these details are obtained from third party information.Show less
1Jportal
1Jportal Web Portal
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in mailer.php in JPortal 2 allows remote attackers to execute arbitrary SQL commands via the to parameter.
1Jportal
1Jportal Web Portal
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter.
1E Vendejo
10.2
Apr 23, 2026
Nov 14, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in articles.php in E-Vendejo 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Phphelpdesk
1Phphelpdesk
Apr 23, 2026
Nov 10, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the login page in phphelpdesk 0.6.16 allows remote attackers to execute arbitrary SQL commands via unspecified parameters related to the "login procedures."
1Jportal
1Jportal Web Portal
Apr 23, 2026
Nov 10, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the to parameter.
1Oracle
1E Business Suite
Apr 23, 2026
Nov 8, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in okxLOV.jsp in Oracle E-Business Suite 11 and 12 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: this is probably the same issue as CVE-2007-5527 or CVE...Show more
SQL injection vulnerability in okxLOV.jsp in Oracle E-Business Suite 11 and 12 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: this is probably the same issue as CVE-2007-5527 or CVE-2007-5528, but there are insufficient details to be sure.Show less
1Infuseum
1Asp Message Board
Apr 23, 2026
Nov 7, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Afcommerce
1Afcommerce
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Amazing Flash AFCommerce allows remote attackers to execute arbitrary SQL commands via the firstname parameter to an unspecified component, a different issue than CVE-2006-3794. NOTE: the...Show more
SQL injection vulnerability in Amazing Flash AFCommerce allows remote attackers to execute arbitrary SQL commands via the firstname parameter to an unspecified component, a different issue than CVE-2006-3794. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Minibb
1Minibb
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL commands via the table parameter to index.php.
1Quirm
1Saxon
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via the template parameter.
1Codewidgets
1Online Event Registration Template
Apr 23, 2026
Oct 29, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in CodeWidgets.com Online Event Registration Template allow remote attackers to execute arbitrary SQL commands via the (1) Email Address and (2) Password fields in (a) login.asp and...Show more
Multiple SQL injection vulnerabilities in CodeWidgets.com Online Event Registration Template allow remote attackers to execute arbitrary SQL commands via the (1) Email Address and (2) Password fields in (a) login.asp and (b) admin_login.asp.Show less