← Back
CWE-89

20,574 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,574)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xoops
1Rha7 Downloads Module
Apr 23, 2026
Apr 11, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other versions up to 1.10, allows remote attackers to execute arbitrary SQL commands via the lid parameter...Show more
SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other versions up to 1.10, allows remote attackers to execute arbitrary SQL commands via the lid parameter.Show less
1Smodbip
1Smodbip
Apr 23, 2026
Apr 10, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers to execute arbitrary SQL commands via the zoom parameter, possibly related to home.php.
1Wordpress
1Wordpress
Apr 23, 2026
Apr 9, 2007
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCatego...Show more
SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.Show less
1Design For Joomla
1D4j Ezine
Apr 23, 2026
Mar 30, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in the DesignForJoomla.com D4J eZine (com_ezine) 2.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in a rea...Show more
SQL injection vulnerability in index.php in the DesignForJoomla.com D4J eZine (com_ezine) 2.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in a read action.Show less
1Jelsoft
1Vbulletin
Apr 23, 2026
Mar 21, 2007
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached Before" field.
1Webwizguide
1Web Wiz Forums
Apr 23, 2026
Mar 20, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrar...Show more
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as demonstrated via the name parameter to forum/pop_up_member_search.asp.Show less
1Koan Software
1Mega Mall
Apr 23, 2026
Mar 20, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or th...Show more
Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php.Show less
1Xigla
1Absolute Image Gallery Xe
Apr 23, 2026
Mar 16, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.
1Oracle
1Apex
Apr 23, 2026
Mar 7, 2007
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV param...Show more
SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV parameter and calculating a matching MD5 checksum for the P_LOV_CHECKSUM parameter. NOTE: it is likely that this issue is subsumed by CVE-2006-5351, but due to lack of details from Oracle, this cannot be proven.Show less
1Li Scripts
1Li Guestbook
Apr 23, 2026
Mar 7, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter. NOTE: it was later reported that...Show more
SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter. NOTE: it was later reported that 1.2 is also affected.Show less
1Dmxready
1Site Engine Manager
Apr 23, 2026
Mar 6, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.asp in DMXReady Site Engine Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter.
1Kubix
1Kubix
Apr 23, 2026
Mar 6, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in includes/functions.php in Kubix 0.7 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the member_id parameter ($id variable) to index.php.
1Angel Learning
1Learning Management Suite
Apr 23, 2026
Mar 3, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Nukescripts
1Nukesentinel
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie.
1Nabocorp
1Nabopoll
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in result.php in Nabopoll 1.2 allows remote attackers to execute arbitrary SQL commands via the surv parameter.
1Webspell
1Webspell
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CV...Show more
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.Show less
1Webspell
1Webspell
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerability than CVE-2006-4782.
1Ban
1Ban
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in connexion.php in Ban 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Sangwan Kim
1Bookmark4u
Apr 23, 2026
Feb 23, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/config.php in Bookmark4U 2.0 and 2.1 allows remote attackers to inject arbitrary SQL command via the sqlcmd parameter.
1Php Nuke
1Emporium Module
Apr 23, 2026
Feb 21, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category_id parameter.