← Back
CWE-89

20,574 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,574)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cplinks
1Cpdynalinks
Apr 23, 2026
Oct 12, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in category.php in cpDynaLinks 1.02 allows remote attackers to execute arbitrary SQL commands via the category parameter.
2Dws Systems Inc.
Ledgersmb
2Ledgersmb
Sql Ledger
Apr 23, 2026
Oct 11, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple SQL injection vulnerabilities in (a) LedgerSMB 1.0.0 through 1.2.7 and (b) DWS Systems SQL-Ledger 2.x allow remote attackers to execute arbitrary SQL commands via (1) the invoice quantity field or (2) the sort f...Show more
Multiple SQL injection vulnerabilities in (a) LedgerSMB 1.0.0 through 1.2.7 and (b) DWS Systems SQL-Ledger 2.x allow remote attackers to execute arbitrary SQL commands via (1) the invoice quantity field or (2) the sort field.Show less
1Modxcms
1Modxcms
Apr 23, 2026
Oct 11, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in mutate_content.dynamic.php in MODx 0.9.6 allow remote attackers to execute arbitrary SQL commands via the (1) documentDirty or (2) modVariables parameter.
1Softbizscripts
1Softbiz Jobs And Recruitment Script
Apr 23, 2026
Oct 9, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Php Homepage M
1Php Homepage M
Apr 23, 2026
Oct 9, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in galerie.php in PHP Homepage M (phpHPm) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.
1Furkan Tastan Blog
1Furkan Tastan Blog
Apr 23, 2026
Oct 8, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in kategori.asp in Furkan Tastan Blog allows remote attackers to execute arbitrary SQL commands via the id parameter in a goster kat action.
1Iscripts
1Multicart
Apr 23, 2026
Oct 6, 2007
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to categorydetail.php and the (2) ddlCategory parameter to search.php.
1Deonixscripts
1Web Template Management System
Apr 23, 2026
Oct 5, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a readmore action.
1Maxdev
1Mdpro
Apr 23, 2026
Oct 5, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substring in a Referer HTTP header.
1Asp Product Catalog
1Asp Product Catalog
Apr 23, 2026
Oct 5, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in catalog.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter and possibly other parameters.
1X Script
1Guestbook
Apr 23, 2026
Oct 3, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in mes_add.php in x-script GuestBook 1.3a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) icq, and (4)...Show more
Multiple SQL injection vulnerabilities in mes_add.php in x-script GuestBook 1.3a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) icq, and (4) website parameters.Show less
1Php Fusion
1Expanded Calendar Module
Apr 23, 2026
Oct 3, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the sel parameter.
1Netkamp
1Netkamp Emlak Scripti
Apr 23, 2026
Oct 3, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detay.asp in Netkamp Emlak Scripti allows remote attackers to execute arbitrary SQL commands via the ilan_id parameter.
1Ohesa Emlak Portali
1Ohesa Emlak Portali
Apr 23, 2026
Oct 3, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Ohesa Emlak Portali allow remote attackers to execute arbitrary SQL commands via the (1) Kategori parameter in satilik.asp and the (2) Emlak parameter in detay.asp.
2Mambads
Mambo
2Mambads
Mambo
Apr 23, 2026
Oct 3, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in the MambAds (com_mambads) 1.5 and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the caid parameter.
1Broadcom
1Brightstor Hierarchical Storage Manager
Apr 23, 2026
Oct 1, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary SQL commands via CsAgent service commands with opc...Show more
Multiple SQL injection vulnerabilities in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary SQL commands via CsAgent service commands with opcodes (1) 0x07, (2) 0x08, (3) 0x09, (4) 0x1E, (5) 0x32, (6) 0x36, (7) 0x40, and possibly others.Show less
1Nukescripts
1Nukesentinel
Apr 23, 2026
Oct 1, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the abget_admin function in includes/nukesentinel.php in NukeSentinel 2.5.12 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie.
1Nukescripts
1Nukesentinel
Apr 23, 2026
Oct 1, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the is_god function in includes/nukesentinel.php in NukeSentinel 2.5.11 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie, a different vec...Show more
SQL injection vulnerability in the is_god function in includes/nukesentinel.php in NukeSentinel 2.5.11 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie, a different vector than CVE-2007-5125.Show less
1Sitex
1Sitex Cms
Apr 23, 2026
Sep 28, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in search.php in SiteX CMS 0.7.3 Beta allows remote attackers to execute arbitrary SQL commands via the search parameter.
1Interspire
1Activekb Nx
Apr 23, 2026
Sep 27, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catId parameter in a browse action. NOTE: it was separately reported that ActiveKB...Show more
SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catId parameter in a browse action. NOTE: it was separately reported that ActiveKB 1.5 is also affected.Show less