← Back
CWE-89

20,588 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,588)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Basic Cms
1Basic Cms
Apr 23, 2026
Jun 20, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands via the page_id parameter.
1Dzoic
1Handshakes
Apr 23, 2026
Jun 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in DZOIC Handshakes 3.5 allows remote attackers to execute arbitrary SQL commands via the fname parameter in a members search action.
1Revokesoft
1Revokebb
Apr 23, 2026
Jun 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in inc/class_search.php in the Search System in RevokeBB 1.0 RC11 allows remote attackers to execute arbitrary SQL commands via the search parameter.
1Dt Centrepiece
1Dt Centrepiece
Apr 23, 2026
Jun 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search.asp in DT Centrepiece 4.0 allows remote attackers to execute arbitrary SQL commands via the searchFor parameter. NOTE: the provenance of this information is unknown; the details are...Show more
SQL injection vulnerability in search.asp in DT Centrepiece 4.0 allows remote attackers to execute arbitrary SQL commands via the searchFor parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Cartkeeper
1Ckgold Shopping Cart
Apr 23, 2026
Jun 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execute arbitrary SQL commands via the category_id parameter, a different vector than CVE-2007-4736.
1Mycrocms
1Mycrocms
Apr 23, 2026
Jun 18, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in MycroCMS 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the entry_id parameter.
1Xigla
1Absolute Poll Manager Xe
Apr 23, 2026
Jun 18, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in search.asp in Xigla Poll Manager XE allows remote authenticated users with administrator role privileges to execute arbitrary SQL commands via the orderby parameter.
1Xigla
1Absolute Image Gallery Xe
Apr 23, 2026
Jun 18, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in gallery.asp in Xigla Absolute Image Gallery XE allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.
1Xigla
1Absolute Live Support Xe
Apr 23, 2026
Jun 18, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in search.asp in Xigla Absolute Live Support XE 5.1 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
1Xigla
1Absolute Form Processor Xe
Apr 23, 2026
Jun 18, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in search.asp in Xigla Absolute Form Processor XE 4.0 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
1Xigla
1Absolute Banner Manager
Apr 23, 2026
Jun 18, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in searchbanners.asp in Xigla Absolute Banner Manager XE 2.0 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
1Xigla
1Absolute News Manager Xe
Apr 23, 2026
Jun 18, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in search.asp in Xigla Absolute News Manager XE 3.2 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
1Jamm Media
1Jamm Cms
Apr 23, 2026
Jun 18, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in JAMM CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Efiction
1Efiction
Apr 23, 2026
Jun 18, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in toplists.php in eFiction 3.0 and 3.4.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the list parameter.
1Paridel
1Pooya Site Builder
Apr 23, 2026
Jun 18, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Pooya Site Builder (PSB) 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) xslIdn parameter to (a) utils/getXsl.aspx, and the (2) part parameter to (b) get...Show more
Multiple SQL injection vulnerabilities in Pooya Site Builder (PSB) 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) xslIdn parameter to (a) utils/getXsl.aspx, and the (2) part parameter to (b) getXml.aspx and (c) getXls.aspx in utils/.Show less
1Torrenttrader
1Torrenttrader Classic
Apr 23, 2026
Jun 18, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in TorrentTrader 1.08 Classic allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) wantusername parameter to account-signup.php, or the (3) receiver par...Show more
Multiple SQL injection vulnerabilities in TorrentTrader 1.08 Classic allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) wantusername parameter to account-signup.php, or the (3) receiver parameter to account-inbox.php in a msg action.Show less
1Gryphon
1Gllcts2
Apr 23, 2026
Jun 17, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL commands via the detail parameter.
1Joomla
1Com Gameq
Apr 23, 2026
Jun 13, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a page action to index.php.
1Gwm
1Galatolo Webmanager
Apr 23, 2026
Jun 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
2Joomla
Rapid Source
2Com Rapidrecipe
Rapid Recipe
Apr 23, 2026
Jun 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to inde...Show more
SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php.Show less