← Back
CWE-89

20,574 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,574)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpcommerce
1Cpcommerce
Apr 23, 2026
Apr 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_product, (2) id_manufacturer, and (3) id_category para...Show more
Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_product, (2) id_manufacturer, and (3) id_category parameters to unspecified components. NOTE: this probably overlaps CVE-2007-2959 and CVE-2007-2890.Show less
1Reddot
1Cms
Apr 23, 2026
Apr 22, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and 7.0, allows remote attackers to execute arbitrary SQL commands via the LngId parameter.
1Carboncommunities
1Carbon Communities
Apr 23, 2026
Apr 18, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to events.asp, the (2) UserName parameter to getpassword.asp,...Show more
Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to events.asp, the (2) UserName parameter to getpassword.asp, and possibly an unspecified parameter to (3) option_Update.asp in an edit action.Show less
1Azrul
1Jom Comment
Apr 23, 2026
Apr 18, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Jom Comment 2.0 build 345 component for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown;...Show more
SQL injection vulnerability in the Jom Comment 2.0 build 345 component for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Xplodphp
1Autotutorials
Apr 23, 2026
Apr 18, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in viewcat.php in XplodPHP AutoTutorials 2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Terong
1Advanced Web Photo Gallery
Apr 23, 2026
Apr 17, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 allows remote attackers to execute arbitrary SQL commands via the photo_id parameter.
1Xpoze
1Xpoze Pro
Apr 23, 2026
Apr 17, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in account/user/mail.html in Xpoze Pro 3.05 and earlier allows remote authenticated users to execute arbitrary SQL commands via the reed parameter.
1Comdev
1Comdev News Publisher
Apr 23, 2026
Apr 17, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter. NOTE: some of these details are obtained from third party...Show more
SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter. NOTE: some of these details are obtained from third party information.Show less
1Scriptsagent
1Links Directory
Apr 23, 2026
Apr 17, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in links.php in Scriptsagent.com Links Directory 1.1 allows remote authenticated users to execute arbitrary SQL commands via the cat_id parameter in a list action.
1Geek247
1Pigmy Sql
Apr 23, 2026
Apr 17, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in getdata.php in PIGMy-SQL 1.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Site Sift Media
1Site Sift Listings
Apr 23, 2026
Apr 17, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Site Sift Listings allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: this issue might be site-specific.
1Pixel Motion
1Pixel Motion Blog
Apr 23, 2026
Apr 17, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie parameter to index.php, possibly related to include/requetesIndex.php.
1Prozilla
1Prozilla Freelancers
Apr 23, 2026
Apr 17, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL commands via the project parameter.
1Prozilla
1Cheats
Apr 23, 2026
Apr 17, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Iscripts
1Socialware
Apr 23, 2026
Apr 16, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.
1724cms
1724cms
Apr 23, 2026
Apr 16, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
1Coronamatrix
1Phpaddressbook
Apr 23, 2026
Apr 16, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1W2b
1Phphotresources
Apr 23, 2026
Apr 16, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cat.php in W2B phpHotResources allows remote attackers to execute arbitrary SQL commands via the kind parameter.
1W2b
1Dating Club
Apr 23, 2026
Apr 16, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in browse.php in W2B DatingClub (aka Dating Club) allows remote attackers to execute arbitrary SQL commands via the age_to parameter in a browsebyCat action.
1Coppermine
1Coppermine Photo Gallery
Apr 23, 2026
Apr 16, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to execute arbitrary SQL commands via an input f...Show more
SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to execute arbitrary SQL commands via an input field associated with the session_id variable, as exploited in the wild in April 2008. NOTE: the fix for CVE-2008-1840 was intended to address this vulnerability, but is actually inapplicable.Show less