← Back
CWE-89

19,889 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (19,889)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webwizguide
1Web Wiz Forums
Apr 23, 2026
Mar 20, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrar...Show more
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as demonstrated via the name parameter to forum/pop_up_member_search.asp.Show less
1Koan Software
1Mega Mall
Apr 23, 2026
Mar 20, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or th...Show more
Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php.Show less
1Xigla
1Absolute Image Gallery Xe
Apr 23, 2026
Mar 16, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.
1Oracle
1Apex
Apr 23, 2026
Mar 7, 2007
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV param...Show more
SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV parameter and calculating a matching MD5 checksum for the P_LOV_CHECKSUM parameter. NOTE: it is likely that this issue is subsumed by CVE-2006-5351, but due to lack of details from Oracle, this cannot be proven.Show less
1Li Scripts
1Li Guestbook
Apr 23, 2026
Mar 7, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter. NOTE: it was later reported that...Show more
SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter. NOTE: it was later reported that 1.2 is also affected.Show less
1Dmxready
1Site Engine Manager
Apr 23, 2026
Mar 6, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.asp in DMXReady Site Engine Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter.
1Kubix
1Kubix
Apr 23, 2026
Mar 6, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in includes/functions.php in Kubix 0.7 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the member_id parameter ($id variable) to index.php.
1Angel Learning
1Learning Management Suite
Apr 23, 2026
Mar 3, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Nukescripts
1Nukesentinel
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie.
1Nabocorp
1Nabopoll
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in result.php in Nabopoll 1.2 allows remote attackers to execute arbitrary SQL commands via the surv parameter.
1Webspell
1Webspell
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CV...Show more
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.Show less
1Webspell
1Webspell
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerability than CVE-2006-4782.
1Ban
1Ban
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in connexion.php in Ban 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Sangwan Kim
1Bookmark4u
Apr 23, 2026
Feb 23, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/config.php in Bookmark4U 2.0 and 2.1 allows remote attackers to inject arbitrary SQL command via the sqlcmd parameter.
1Php Nuke
1Emporium Module
Apr 23, 2026
Feb 21, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
1Scriptdungeon
1Xlatunes
Apr 23, 2026
Feb 21, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in view mode. NOTE: some of these details are obtained from third par...Show more
SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in view mode. NOTE: some of these details are obtained from third party information.Show less
1Phpcc
1Phpcc
Apr 23, 2026
Feb 16, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in nickpage.php in phpCC 4.2 beta and earlier allows remote attackers to execute arbitrary SQL commands via the npid parameter in a sign_gb action.
1Aspcode.net
1Pollmentor
Apr 23, 2026
Feb 16, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin_poll.asp in PollMentor 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to pollmentorres.asp.
1Mcrefer
1Mcrefer
Apr 23, 2026
Feb 12, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in install.php in mcRefer allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this issue has been disputed by a third party, stating that the file does not...Show more
SQL injection vulnerability in install.php in mcRefer allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this issue has been disputed by a third party, stating that the file does not use a SQL databaseShow less
1Globalmegacorp
1Dvddb
Apr 23, 2026
Feb 6, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: this issue has been disputed by a reliable third party, w...Show more
SQL injection vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: this issue has been disputed by a reliable third party, who states that inc/common.php only contains function definitionsShow less