CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,170
Total CVEs
104
Critical
1,277
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
221
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,170)

CVE-2025-14215
7.3

This SQL injection vulnerability in Currency Exchange System 1.0 allows attackers to execute arbitrary SQL commands through the ID parameter in /edit....

Dec 8, 2025
CVE-2025-14210
7.3

CVE-2025-14210 is an SQL injection vulnerability in Advanced Library Management System 1.0 that allows remote attackers to execute arbitrary SQL comma...

Dec 8, 2025
CVE-2025-14211
7.3

CVE-2025-14211 is a SQL injection vulnerability in Advanced Library Management System 1.0 that allows attackers to manipulate database queries via the...

Dec 8, 2025
CVE-2025-14212
7.3

This CVE describes a SQL injection vulnerability in Advanced Library Management System 1.0's member_search.php file. Attackers can manipulate the roll...

Dec 8, 2025
CVE-2025-14209
7.3

Campcodes School File Management System 1.0 contains a SQL injection vulnerability in the /update_query.php file via the stud_id parameter. This allow...

Dec 8, 2025
CVE-2025-14207
7.3

This CVE describes a SQL injection vulnerability in the Hotel-Management-System's invoiceprint.php file where the ID parameter can be manipulated. Att...

Dec 8, 2025
CVE-2025-14192
7.3

This CVE describes a SQL injection vulnerability in the RashminDungrani online-banking application's login functionality. Attackers can manipulate the...

Dec 7, 2025
CVE-2025-14190
7.3

This SQL injection vulnerability in Chanjet TPlus allows remote attackers to execute arbitrary SQL commands via the 'currentAccId' parameter in the Mu...

Dec 7, 2025
CVE-2025-14189
7.3

This CVE describes a SQL injection vulnerability in Chanjet CRM through version 20251121. Attackers can exploit the gblOrgID parameter in /tools/jxf_d...

Dec 7, 2025
CVE-2025-14091
7.3

This CVE describes a SQL injection vulnerability in TrippWasTaken PHP-Guitar-Shop that allows remote attackers to execute arbitrary SQL commands via t...

Dec 5, 2025
CVE-2025-13792
7.3

This vulnerability allows remote attackers to execute arbitrary code on Qualitor systems by manipulating the 'passageiros' parameter in the /html/st/s...

Nov 30, 2025
CVE-2025-13788
7.3

This CVE describes a SQL injection vulnerability in Chanjet CRM's /tools/upgradeattribute.php file, specifically in the gblOrgID parameter. Attackers ...

Nov 30, 2025
CVE-2025-13786
7.3

This CVE describes a remote code injection vulnerability in taosir WTCMS that allows attackers to execute arbitrary code by manipulating the 'content'...

Nov 30, 2025
CVE-2025-13782
7.3

This CVE describes an SQL injection vulnerability in taosir WTCMS's SlideController component. Attackers can exploit this to execute arbitrary SQL com...

Nov 30, 2025
CVE-2025-13585
7.3

CVE-2025-13585 is a SQL injection vulnerability in itsourcecode COVID Tracking System 1.0 that allows attackers to execute arbitrary SQL commands via ...

Nov 24, 2025
CVE-2025-13583
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against Question Paper Generator 1.0 by manipulating the Fname parameter i...

Nov 24, 2025
CVE-2025-13582
7.3

CVE-2025-13582 is a SQL injection vulnerability in Jonnys Liquor 1.0 that allows attackers to execute arbitrary SQL commands through the Product param...

Nov 24, 2025
CVE-2025-13578
7.3

CVE-2025-13578 is an SQL injection vulnerability in code-projects Library System 1.0 that allows attackers to manipulate database queries through the ...

Nov 24, 2025
CVE-2025-13572
7.3

This SQL injection vulnerability in Advanced Library Management System 1.0 allows attackers to manipulate database queries through the admin_id parame...

Nov 23, 2025
CVE-2025-13561
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Company Website CMS 1.0 through the Username parame...

Nov 23, 2025
CVE-2025-13562
7.3

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-852 routers by exploiting a command injection flaw in the /gena...

Nov 23, 2025
CVE-2025-13557
7.3

Campcodes Online Polling System 1.0 contains a SQL injection vulnerability in the /registeracc.php file's email parameter. This allows remote attacker...

Nov 23, 2025
CVE-2025-13560
7.3

This SQL injection vulnerability in SourceCodester Company Website CMS 1.0 allows attackers to manipulate database queries through the email parameter...

Nov 23, 2025
CVE-2025-13556
7.3

CVE-2025-13556 is an SQL injection vulnerability in Campcodes Online Polling System 1.0 that allows remote attackers to execute arbitrary SQL commands...

Nov 23, 2025
CVE-2025-13555
7.3

Campcodes School File Management System 1.0 contains a SQL injection vulnerability in the login component's stud_no parameter. Attackers can remotely ...

Nov 23, 2025
CVE-2025-13554
7.3

Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the login component's username parameter. Attackers can remotely ex...

Nov 23, 2025
CVE-2025-13485
7.3

CVE-2025-13485 is an SQL injection vulnerability in itsourcecode Online File Management System 1.0 that allows attackers to execute arbitrary SQL comm...

Nov 21, 2025
CVE-2025-13451
7.3

This SQL injection vulnerability in SourceCodester Online Shop Project 1.0 allows attackers to manipulate database queries through the Search paramete...

Nov 20, 2025
CVE-2025-13442
7.3

This CVE describes a command injection vulnerability in UTT 进取 750W devices up to version 3.2.2-191225. Attackers can remotely execute arbitrary c...

Nov 20, 2025
CVE-2025-13449
7.3

This SQL injection vulnerability in code-projects Online Shop Project 1.0 allows attackers to manipulate database queries through the password paramet...

Nov 20, 2025
CVE-2025-13422
7.3

This is an SQL injection vulnerability in freeprojectscodes Sports Club Management System 1.0 that allows remote attackers to execute arbitrary SQL co...

Nov 20, 2025
CVE-2025-13421
7.3

This is an SQL injection vulnerability in itsourcecode Human Resource Management System 1.0 that allows attackers to execute arbitrary SQL commands th...

Nov 19, 2025
CVE-2025-13420
7.3

CVE-2025-13420 is a SQL injection vulnerability in itsourcecode Human Resource Management System 1.0 that allows remote attackers to execute arbitrary...

Nov 19, 2025
CVE-2025-13410
7.3

This SQL injection vulnerability in Campcodes Retro Basketball Shoes Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via th...

Nov 19, 2025
CVE-2025-13395
7.3

This CVE describes a SQL injection vulnerability in the Login function of codehub666 94list software. Attackers can remotely exploit this flaw to exec...

Nov 19, 2025
CVE-2025-13344
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the Username parameter in the /ajax.php?action=login endpoint of Sour...

Nov 18, 2025
CVE-2025-13323
7.3

This SQL injection vulnerability in Simple Pizza Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in...

Nov 18, 2025
CVE-2025-13300
7.3

This SQL injection vulnerability in itsourcecode Web-Based Internet Laboratory Management System 1.0 allows attackers to execute arbitrary SQL command...

Nov 17, 2025
CVE-2025-13301
7.3

This SQL injection vulnerability in itsourcecode Web-Based Internet Laboratory Management System 1.0 allows remote attackers to execute arbitrary SQL ...

Nov 17, 2025
CVE-2025-13298
7.3

CVE-2025-13298 is a SQL injection vulnerability in itsourcecode Web-Based Internet Laboratory Management System 1.0 that allows remote attackers to ex...

Nov 17, 2025
CVE-2025-13299
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against itsourcecode Web-Based Internet Laboratory Management System 1.0 t...

Nov 17, 2025
CVE-2025-13297
7.3

This SQL injection vulnerability in itsourcecode Web-Based Internet Laboratory Management System 1.0 allows remote attackers to execute arbitrary SQL ...

Nov 17, 2025
CVE-2025-13291
7.3

CVE-2025-13291 is a SQL injection vulnerability in Campcodes Supplier Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Nov 17, 2025
CVE-2025-13285
7.3

CVE-2025-13285 is an SQL injection vulnerability in itsourcecode Online Voting System 1.0 that allows attackers to manipulate database queries via the...

Nov 17, 2025
CVE-2025-13280
7.3

CVE-2025-13280 is an SQL injection vulnerability in CodeAstro Simple Inventory System 1.0 that allows attackers to manipulate database queries through...

Nov 17, 2025
CVE-2025-13277
7.3

CVE-2025-13277 is a SQL injection vulnerability in Nero Social Networking Site 1.0 that allows remote attackers to execute arbitrary SQL commands via ...

Nov 17, 2025
CVE-2025-13276
7.3

This SQL injection vulnerability in g33kyrash Online-Banking-System allows attackers to manipulate database queries through the Username parameter in ...

Nov 17, 2025
CVE-2025-13272
7.3

This SQL injection vulnerability in Campcodes School Fees Payment Management System 1.0 allows attackers to execute arbitrary SQL commands through the...

Nov 17, 2025
CVE-2025-13271
7.3

Campcodes School Fees Payment Management System 1.0 contains a SQL injection vulnerability in the login function via the Username parameter. This allo...

Nov 17, 2025
CVE-2025-13257
7.3

This SQL injection vulnerability in itsourcecode Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands through the...

Nov 17, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,170 CVEs classified as CWE-74, with 104 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free