← Back
CWE-89

20,589 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,589)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webblizzard
1Content Management System
Apr 23, 2026
Jul 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.
1Tritoncms
1Triton Cms Pro
Apr 23, 2026
Jul 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Triton CMS Pro allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.
1Orbitscripts
2Smartppc
Smartppc Pro
Apr 23, 2026
Jul 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary SQL commands via the idDirectory parameter.
2Phpnuke
Warpspeed
24ndvddb
4ndvddb
Apr 23, 2026
Jul 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_dvd action.
1Ashopsoftware
1Ashop Deluxe
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.
1Barenuked
1Barenuked Cms
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in admin/index.php in BareNuked CMS 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the password parameter.
1Joomla
1Com Beamospetition
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php.
1Powie
1Psys
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showid parameter.
1Catviz
1Catviz
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL commands via the (1) foreign_key_value parameter in the news page and (2) webpage parameter in the...Show more
Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL commands via the (1) foreign_key_value parameter in the news page and (2) webpage parameter in the webpage_multi_edit form.Show less
1Mole Group
1Lastminute Script
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Mole Group Lastminute Script 4.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Mole Group
1Hotel Script
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Mole Group Hotel Script 1.0 allows remote attackers to execute arbitrary SQL commands via the file parameter.
1Mole Group
1Real Estate Script
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.
1Xerox
1Centreware Web
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to execute arbitrary SQL commands via the unspecified vectors.
1Dreamlevels
1Dream Pics Builder
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in DreamPics Builder allows remote attackers to execute arbitrary SQL commands via the page parameter.
1Phpmotion
1Phpmotion
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the vid parameter.
1Drupal
1Taxonomy Autotagger Module
Apr 23, 2026
Jul 9, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to execute arbitrary SQL commands via unspecified vecto...Show more
SQL injection vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to execute arbitrary SQL commands via unspecified vectors.Show less
1Blognplus
1Blognplus
Apr 23, 2026
Jul 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in index.php in BlognPlus (BURO GUN +) 2.5.5 MySQL and PostgreSQL editions allow remote attackers to execute arbitrary SQL commands via the (1) p, (2) e, (3) d, and (4) m parameters...Show more
Multiple SQL injection vulnerabilities in index.php in BlognPlus (BURO GUN +) 2.5.5 MySQL and PostgreSQL editions allow remote attackers to execute arbitrary SQL commands via the (1) p, (2) e, (3) d, and (4) m parameters, a different vulnerability than CVE-2008-2819.Show less
1Xpoze
1Xpoze Pro
Apr 23, 2026
Jul 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in user.html in Xpoze Pro 3.06 (aka Xpoze Pro CMS 2008) allows remote attackers to execute arbitrary SQL commands via the uid parameter.
2Brightcode
Joomla
2Brightcode Weblinks Module
Com Brightweblinks
Apr 23, 2026
Jul 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.
1Fascript
1Faname
Apr 23, 2026
Jul 9, 2008
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
SQL injection vulnerability in class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might be the same issue as CVE-2008-0328...Show more
SQL injection vulnerability in class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might be the same issue as CVE-2008-0328.Show less