← Back
CWE-89

20,574 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,574)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Coppermine
1Coppermine Photo Gallery
Apr 23, 2026
Apr 16, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type...Show more
SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is used for an upload.Show less
1Bosdev
1Bosclassifieds Ads Systems
Apr 23, 2026
Apr 16, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php.
1Mygamingladder
1Mygamingladder
Apr 23, 2026
Apr 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ladder.php in My Gaming Ladder 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the ladderid parameter.
1Prozilla
1Forum
Apr 23, 2026
Apr 15, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.
1Prozilla
1Entertainers
Apr 23, 2026
Apr 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: some of these details are obtained from third...Show more
SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: some of these details are obtained from third party information.Show less
1Pligg
1Pligg Cms
Apr 23, 2026
Apr 14, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in editlink.php in Pligg 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Blogator Script
1Blogator Script
Apr 23, 2026
Apr 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in _blogadata/include/sond_result.php in Blogator-script 0.95 allows remote attackers to execute arbitrary SQL commands via the id_art parameter.
2Jeuxflash
Kwsphp
2Jeuxflash Module
Kwsphp
Apr 23, 2026
Apr 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the jeuxflash module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php, a different vector than CVE-2007-4922.
1Kwsphp
1Kwsphp
Apr 23, 2026
Apr 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the C_ID parameter to index.php.
1Livecart
1Livecart
Apr 23, 2026
Apr 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to the /category URI.
1Pragmaticutopia
1Com Puarcade
Apr 23, 2026
Apr 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in puarcade.class.php 2.2 and earlier in the Pragmatic Utopia PU Arcade (com_puarcade) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter to...Show more
SQL injection vulnerability in puarcade.class.php 2.2 and earlier in the Pragmatic Utopia PU Arcade (com_puarcade) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter to index.php.Show less
1Predictionfootball
1Predictionfootball
Apr 23, 2026
Apr 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in showpredictionsformatch.php in Prediction Football 1.x allows remote attackers to execute arbitrary SQL commands via the matchid parameter in a dupa action.
1Myknowledgequest
1Knowledgequest
Apr 23, 2026
Apr 11, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kqid parameter to (a) articletext.php and (b) articlet...Show more
Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kqid parameter to (a) articletext.php and (b) articletextonly.php and the (2) username parameter to (c) logincheck.php.Show less
1Auracms
1Auracms
Apr 23, 2026
Apr 9, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter.
1Fascript
1Faphoto
Apr 23, 2026
Apr 9, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in show.php in FaScript FaPhoto 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Desiquintans
1Writers Block Cms
Apr 23, 2026
Apr 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in permalink.php in Desi Quintans Writer's Block CMS 3.8a allows remote attackers to execute arbitrary SQL commands via the PostID parameter.
1Myiosoft
1Easynews
Apr 23, 2026
Apr 2, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0 allows remote attackers to execute arbitrary SQL commands via the read parameter in an edp_Help_Internal_News action.
2Arnos Toolbox
Wordpress
2Wp Download
Wp Download
Apr 23, 2026
Apr 2, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.
1Savas Place
1Savas Link Manager
Apr 23, 2026
Apr 2, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in viewlinks.php in Sava's Link Manager 2.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. NOTE: the provenance of this information is unknown; the deta...Show more
SQL injection vulnerability in viewlinks.php in Sava's Link Manager 2.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Efestech
1Video
Apr 23, 2026
Apr 2, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in default.asp in EfesTECH Video 5.0 allows remote attackers to execute arbitrary SQL commands via the catID parameter.