← Back
CWE-89

20,574 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,574)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pnflashgames
1Pnflashgames
Apr 23, 2026
Apr 30, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a dis...Show more
SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a display action.Show less
1Postnuke Software Foundation
1Postschedule
Apr 23, 2026
Apr 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the eid parameter in an event action.
1Acidcat
1Acidcat Cms
Apr 23, 2026
Apr 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) cID parameter to default.asp and the (2) username parameter to main_login2.asp.
1Wordpress
1Wpss
Apr 23, 2026
Apr 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter.
1Cogites
1E Reserve
Apr 23, 2026
Apr 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in E-RESERV 2.1 allows remote attackers to execute arbitrary SQL commands via the ID_loc parameter.
1Cezannesw
1Cezanne
Apr 23, 2026
Apr 27, 2008
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Multiple SQL injection vulnerabilities in Cezanne 7 allow remote authenticated users to execute arbitrary SQL commands via the FUNID parameter to (1) CFLookup.asp and (2) CznCommon/CznCustomContainer.asp.
1Php Resource
1Voice Of Web Allmyguests
Apr 23, 2026
Apr 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary SQL commands via the AMG_id parameter in a comments action.
1Easyscripts
1Tr Script News
Apr 23, 2026
Apr 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands via the nb parameter in voir mode.
1Webcalendar
1Web Calendar Pro
Apr 23, 2026
Apr 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
1Aspindir
1Philboard
Apr 23, 2026
Apr 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in W1L3D4 Philboard 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) topic parameters to (a) philboard_reply.asp, and the (3) forumid parameter to...Show more
Multiple SQL injection vulnerabilities in W1L3D4 Philboard 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) topic parameters to (a) philboard_reply.asp, and the (3) forumid parameter to (b) philboard_newtopic.asp, different vectors than CVE-2007-2641 and CVE-2007-0920.Show less
1Classifieds Caffe
1Classifieds Caffe
Apr 23, 2026
Apr 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in an add action. NOTE: this issue might be site-specific.
1Joomla
1Joomla
Apr 23, 2026
Apr 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Filiale 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the idFiliale parameter.
1Crazy Goomba
1Crazy Goomba
Apr 23, 2026
Apr 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in commentaires.php in Crazy Goomba 1.2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
15th Avenue Software
15th Avenue Shopping Cart
Apr 23, 2026
Apr 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter.
1Yourfreeworld
1Apartment Search Script
Apr 23, 2026
Apr 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in listtest.php in YourFreeWorld Apartment Search Script allows remote attackers to execute arbitrary SQL commands via the r parameter.
1Php Fusion
1Php Fusion
Apr 23, 2026
Apr 23, 2008
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands...Show more
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] parameter in a link submission action. NOTE: it was later reported that 7.00.2 is also affected.Show less
1Devworx
1Blogworx
Apr 23, 2026
Apr 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Lasernet Cms
1Lasernet Cms
Apr 23, 2026
Apr 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the new parameter in a new action.
11024 Cms
11024 Cms
Apr 23, 2026
Apr 22, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in includes/system.php in 1024 CMS 1.4.2 beta and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a cookpass cookie.
1Chadha Software Technologies
1Phpkb Knowledge Base
Apr 23, 2026
Apr 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.