← Back
CWE-89

19,889 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (19,889)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Limbo Cms
1Limbo Cms
Apr 16, 2026
May 15, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute arbitrary SQL commands via the catid parameter.
1Ozzywork
1Galeri
Apr 16, 2026
May 11, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin_default.asp in OzzyWork Galeri allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password fields.
1Flexcustomer
1Flexcustomer
Apr 16, 2026
May 9, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in FlexCustomer 0.0.4 and earlier allows remote attackers to bypass authentication and execute arbitrary SQL commands via the admin and ordinary user interface, probably involving the (1) chec...Show more
SQL injection vulnerability in FlexCustomer 0.0.4 and earlier allows remote attackers to bypass authentication and execute arbitrary SQL commands via the admin and ordinary user interface, probably involving the (1) checkuser and (2) checkpass parameters to (a) admin/index.php, and (3) username and (4) password parameters to (b) index.php. NOTE: it was later reported that 0.0.6 is also affected.Show less
1Maxxcode
1Maxxschedule
Apr 16, 2026
May 9, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to execute arbitrary SQL commands via the txtLogon parameter.
1Tuomas Airaksinen
1Newsadmin
Apr 16, 2026
May 9, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in readarticle.php in Newsadmin 1.1 allows remote attackers to execute arbitrary SQL commands via the nid parameter.
1Plogger
1Plogger
Apr 16, 2026
May 3, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in gallery.php in Plogger Beta 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter, when the level is set to "slideshow". NOTE: This is a different...Show more
SQL injection vulnerability in gallery.php in Plogger Beta 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter, when the level is set to "slideshow". NOTE: This is a different vulnerability than CVE-2005-4246.Show less
1Deltascripts
1Pro Publish
Apr 16, 2026
May 1, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Pro Publish 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameter to (a) admin/login.php, (3) find_str parameter to (b) search...Show more
Multiple SQL injection vulnerabilities in Pro Publish 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameter to (a) admin/login.php, (3) find_str parameter to (b) search.php, or (4) artid parameter to (c) art.php, or (5) catid parameter to (d) cat.php.Show less
1Mybulletinboard
1Mybulletinboard
Apr 16, 2026
Apr 29, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
SQL injection vulnerability in MyBB (MyBulletinBoard) 1.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the (1) query string ($querystring variable) in (a) admin/adminlogs.php, which...Show more
SQL injection vulnerability in MyBB (MyBulletinBoard) 1.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the (1) query string ($querystring variable) in (a) admin/adminlogs.php, which is not properly handled by adminfunctions.php; or (2) setid, (3) expand, (4) title, or (5) sid2 parameters to (b) admin/templates.php.Show less
1Mysmartbb
1Mysmartbb
Apr 16, 2026
Apr 29, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in misc.php in MySmartBB 1.1.x allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) username parameters.
1Flexbb
1Flexbb
Apr 16, 2026
Apr 21, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in inc/start.php in FlexBB 0.5.5 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_username COOKIE parameter.
1Pcpin
1Pcpin Chat
Apr 16, 2026
Apr 21, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in PCPIN Chat 5.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (login parameter) to main.php.
1Oracle
1Database Server
Apr 16, 2026
Apr 20, 2006
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.5 allows remote attackers to execute arbitrary SQL commands via the DELETE_FROM_TABLE function in the DBMS_LOGMNR_SESSION (Log Miner) package, aka...Show more
SQL injection vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.5 allows remote attackers to execute arbitrary SQL commands via the DELETE_FROM_TABLE function in the DBMS_LOGMNR_SESSION (Log Miner) package, aka Vuln# DB06.Show less
1Michiel Van Baak
1Mvblog
Apr 16, 2026
Apr 12, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in MvBlog before 1.6 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
1Maxdev
1Md Pro
Apr 16, 2026
Apr 11, 2006
N/A· v4
N/A· v3
6.4 MEDIUM· v2
SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to execute arbitrary SQL commands vi...Show more
SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a display action, which is not properly handled in PNuserapi.PHP.Show less
1Oneorzero
1Oneorzero
Apr 16, 2026
Mar 30, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in the kans action.
1Tilde
1Tilde Cms
Apr 16, 2026
Mar 30, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Tilde CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Ubbcentral
1Ubb.threads
Apr 16, 2026
Mar 28, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number parameter.
1Musicbox
1Musicbox
Apr 16, 2026
Mar 23, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in MusicBox 2.3 Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) type, or (3) show parameter to (a) index.php; or the (4) message1 or (5) message...Show more
Multiple SQL injection vulnerabilities in MusicBox 2.3 Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) type, or (3) show parameter to (a) index.php; or the (4) message1 or (5) message parameter to (b) cart.php.Show less
1Phpwebsite
1Phpwebsite
Apr 16, 2026
Mar 21, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid parameter to (1) friend.php or (2) article.php.
1Upoint
1@1 File Store
Apr 16, 2026
Mar 19, 2006
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) del...Show more
SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php. NOTE: it was later reported that vectors 12 and 13 also affect @1 File Store PRO 3.2.Show less