← Back
CWE-89

20,587 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,587)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Raknet
1Autopatcher Server
Apr 23, 2026
Jun 3, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Autopatcher server plugin in RakNet before 3.23 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Haudenschilt
1Battlenet Clan Script
Apr 23, 2026
Jun 3, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showmember parameter in...Show more
SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showmember parameter in a members action.Show less
1Yabsoft
1Mega File Hosting Script
Apr 23, 2026
Jun 3, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid parameter.
1Wordpress
1Upload File Plugin
Apr 23, 2026
May 29, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the f_id parameter.
1Excuse Online
1Excuse Online
Apr 23, 2026
May 29, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in pwd.asp in Excuse Online allows remote attackers to execute arbitrary SQL commands via the pID parameter.
1Simpel Side
1Weblosning
Apr 23, 2026
May 29, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Simpel Side Weblosning 1 through 4 allow remote attackers to execute arbitrary SQL commands via the (1) mainid and (2) id parameters to index2.php.
1Simpel Side
1Netbutik
Apr 23, 2026
May 29, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Simpel Side Netbutik 1 through 4 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to netbutik.php and the (2) id parameter to product.php.
1Henning Stoverud
1Phphotoalbum
Apr 23, 2026
May 29, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in PHPhotoalbum 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) album parameter to thumbnails.php and the (2) pid parameter to displayimage.php.
1Mambo Foundation
1Mambo
Apr 23, 2026
May 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in index.php in Mambo before 4.6.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) articleid and (2) mcname parameters. NOT...Show more
Multiple SQL injection vulnerabilities in index.php in Mambo before 4.6.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) articleid and (2) mcname parameters. NOTE: some of these details are obtained from third party information.Show less
1Badongo
1Campus Bulletin Board
Apr 23, 2026
May 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Campus Bulletin Board 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to post3/view.asp and the (2) review parameter to post3/book.asp.
1Hotscripts
1Ablespace
Apr 23, 2026
May 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in adv_cat.php in AbleSpace 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
1Typo3
1Sg Zfelib
Apr 23, 2026
May 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Library for Frontend Plugins (aka sg_zfelib) extension 1.1.512 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified "user input."
1Maxsite
1Maxsite
Apr 23, 2026
May 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a webboard action.
1Xomol
1Xomol Cms
Apr 23, 2026
May 28, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in Xomol CMS 1.20071213, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the email parameter.
1Badongo
1Phpfix
Apr 23, 2026
May 28, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in phpFix 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) kind parameter to fix/browse.php and the (2) account parameter to auth/00_pass.php.
1Mx System
1Mxbb Portal
Apr 23, 2026
May 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in MxBB (aka MX-System) Portal 2.7.3 allows remote attackers to execute arbitrary SQL commands via the page parameter.
1Netious
1Netious Cms
Apr 23, 2026
May 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Netious CMS 0.4 allows remote attackers to execute arbitrary SQL commands via the pageid parameter, a different vector than CVE-2006-4047.
1Vbulletin
1Vbulletin
Apr 23, 2026
May 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in faq.php in vBulletin 3.7.0 Gold allows remote attackers to execute arbitrary SQL commands via the q parameter in a search action.
1Bitmixsoft
1Php Jokesite
Apr 23, 2026
May 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in jokes_category.php in PHP-Jokesite 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
1Comicshout
1Comicshout
Apr 23, 2026
May 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the comic_id parameter.