CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,170
Total CVEs
104
Critical
1,277
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
221
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,170)

CVE-2025-13248
7.3

This CVE describes a SQL injection vulnerability in SourceCodester Patients Waiting Area Queue Management System 1.0. Attackers can remotely exploit t...

Nov 16, 2025
CVE-2025-13247
7.3

This SQL injection vulnerability in PHPGurukul Tourism Management System 1.0 allows attackers to manipulate database queries through the uid parameter...

Nov 16, 2025
CVE-2025-13242
7.3

This SQL injection vulnerability in Student Information System 2.0 allows attackers to execute arbitrary SQL commands through the /register.php endpoi...

Nov 16, 2025
CVE-2025-13241
7.3

CVE-2025-13241 is an SQL injection vulnerability in code-projects Student Information System 2.0 that allows remote attackers to execute arbitrary SQL...

Nov 16, 2025
CVE-2025-13240
7.3

CVE-2025-13240 is an SQL injection vulnerability in code-projects Student Information System 2.0 that allows attackers to manipulate database queries ...

Nov 16, 2025
CVE-2025-13237
7.3

CVE-2025-13237 is an SQL injection vulnerability in itsourcecode Inventory Management System 1.0 that allows remote attackers to execute arbitrary SQL...

Nov 16, 2025
CVE-2025-13235
7.3

CVE-2025-13235 is an SQL injection vulnerability in itsourcecode Inventory Management System 1.0 that allows attackers to manipulate database queries ...

Nov 16, 2025
CVE-2025-13233
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands through the /index.php?q=single-item endpoint in itsourcecode Inventory M...

Nov 16, 2025
CVE-2025-13203
7.3

This SQL injection vulnerability in Simple Cafe Ordering System 1.0 allows attackers to manipulate database queries through the studentnum parameter i...

Nov 15, 2025
CVE-2025-13201
7.3

CVE-2025-13201 is an SQL injection vulnerability in code-projects Simple Cafe Ordering System 1.0 that allows attackers to execute arbitrary SQL comma...

Nov 15, 2025
CVE-2025-13169
7.3

CVE-2025-13169 is an SQL injection vulnerability in Simple Online Hotel Reservation System 1.0 that allows remote attackers to execute arbitrary SQL c...

Nov 14, 2025
CVE-2025-13170
7.3

CVE-2025-13170 is an SQL injection vulnerability in Simple Online Hotel Reservation System 1.0 that allows attackers to manipulate database queries vi...

Nov 14, 2025
CVE-2025-13122
7.3

This SQL injection vulnerability in SourceCodester Patients Waiting Area Queue Management System 1.0 allows attackers to manipulate database queries t...

Nov 13, 2025
CVE-2025-13121
7.3

CVE-2025-13121 is an SQL injection vulnerability in the Liketea 1.0.0 API endpoint that allows remote attackers to execute arbitrary SQL commands by m...

Nov 13, 2025
CVE-2025-13060
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Survey Application System 1.0 via the ID parameter ...

Nov 12, 2025
CVE-2025-12929
7.3

This SQL injection vulnerability in SourceCodester Survey Application System 1.0 allows attackers to manipulate database queries through the fullname ...

Nov 10, 2025
CVE-2025-12617
7.3

CVE-2025-12617 is a SQL injection vulnerability in itsourcecode Billing System 1.0 that allows remote attackers to execute arbitrary SQL commands via ...

Nov 3, 2025
CVE-2025-12337
7.3

CVE-2025-12337 is a SQL injection vulnerability in Campcodes Retro Basketball Shoes Online Store 1.0 that allows remote attackers to execute arbitrary...

Oct 28, 2025
CVE-2025-12339
7.3

This SQL injection vulnerability in Campcodes Retro Basketball Shoes Online Store 1.0 allows attackers to manipulate database queries through the /adm...

Oct 28, 2025
CVE-2025-12325
7.3

This SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows attackers to manipulate database queries through the email ...

Oct 27, 2025
CVE-2025-12316
7.3

This SQL injection vulnerability in code-projects Courier Management System 1.0 allows attackers to manipulate database queries through the OfficeName...

Oct 27, 2025
CVE-2025-12308
7.3

This CVE describes a SQL injection vulnerability in Nero Social Networking Site 1.0's deletemessage.php file. Attackers can manipulate the message_id ...

Oct 27, 2025
CVE-2025-12306
7.3

CVE-2025-12306 is a SQL injection vulnerability in Nero Social Networking Site 1.0 that allows remote attackers to execute arbitrary SQL commands via ...

Oct 27, 2025
CVE-2025-12292
7.3

CVE-2025-12292 is an SQL injection vulnerability in SourceCodester Point of Sales 1.0 that allows remote attackers to execute arbitrary SQL commands v...

Oct 27, 2025
CVE-2025-12293
7.3

This SQL injection vulnerability in SourceCodester Point of Sales 1.0 allows remote attackers to manipulate database queries through the Category para...

Oct 27, 2025
CVE-2025-12277
7.3

This CVE describes a SQL injection vulnerability in Abdullah-Hasan-Sajjad Online-School's studentLogin.php file, specifically in the Email parameter. ...

Oct 27, 2025
CVE-2025-12257
7.3

This SQL injection vulnerability in SourceCodester Online Student Result System 1.0 allows attackers to manipulate database queries through the ID par...

Oct 27, 2025
CVE-2025-12253
7.3

This CVE describes a SQL injection vulnerability in AMTT Hotel Broadband Operation System 1.0 affecting the /user/portal/get_expiredtime.php endpoint ...

Oct 27, 2025
CVE-2025-12215
7.3

This SQL injection vulnerability in Projectworlds Online Shopping System 1.0 allows attackers to execute arbitrary SQL commands via the 'keywords' par...

Oct 27, 2025
CVE-2025-12208
7.3

This SQL injection vulnerability in SourceCodester Best House Rental Management System 1.0 allows attackers to manipulate database queries through the...

Oct 27, 2025
CVE-2025-11736
7.3

CVE-2025-11736 is an SQL injection vulnerability in itsourcecode Online Examination System 1.0 that allows remote attackers to execute arbitrary SQL c...

Oct 14, 2025
CVE-2025-11662
7.3

This CVE describes a SQL injection vulnerability in SourceCodester Best Salon Management System 1.0. Attackers can manipulate the serv_id parameter in...

Oct 13, 2025
CVE-2025-11654
7.3

This CVE describes an SQL injection vulnerability in the Inferno Online Clothing Store's /log.php file, specifically in the cemail/password parameters...

Oct 13, 2025
CVE-2025-11614
7.3

This SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows attackers to manipulate database queries through the editid...

Oct 11, 2025
CVE-2025-11608
7.3

CVE-2025-11608 is an SQL injection vulnerability in code-projects E-Banking System 1.0 that allows remote attackers to execute arbitrary SQL commands ...

Oct 11, 2025
CVE-2025-11604
7.3

CVE-2025-11604 is a SQL injection vulnerability in projectworlds Online Ordering Food System 1.0 that allows attackers to manipulate database queries ...

Oct 11, 2025
CVE-2025-11601
7.3

This SQL injection vulnerability in SourceCodester Online Student Result System 1.0 allows attackers to manipulate database queries through the Userna...

Oct 11, 2025
CVE-2025-11599
7.3

CVE-2025-11599 is a SQL injection vulnerability in Campcodes Online Apartment Visitor Management System 1.0 that allows remote attackers to execute ar...

Oct 11, 2025
CVE-2025-11596
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against code-projects E-Commerce Website 1.0 by manipulating the order_id ...

Oct 11, 2025
CVE-2025-11585
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against Project Monitoring System 1.0 through the uid parameter in /usered...

Oct 10, 2025
CVE-2025-11584
7.3

This vulnerability allows attackers to execute arbitrary SQL commands through the txtspecialization parameter in the searchjob.php file of Online Job ...

Oct 10, 2025
CVE-2025-11582
7.3

CVE-2025-11582 is an SQL injection vulnerability in code-projects Online Job Search Engine 1.0 that allows remote attackers to execute arbitrary SQL c...

Oct 10, 2025
CVE-2025-11557
7.3

This SQL injection vulnerability in Gate Pass Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'fullname' param...

Oct 9, 2025
CVE-2025-11558
7.3

This SQL injection vulnerability in code-projects E-Commerce Website 1.0 allows remote attackers to execute arbitrary SQL commands via the Search para...

Oct 9, 2025
CVE-2025-11555
7.3

CVE-2025-11555 is an SQL injection vulnerability in Campcodes Online Learning Management System 1.0 that allows attackers to manipulate database queri...

Oct 9, 2025
CVE-2025-11513
7.3

This SQL injection vulnerability in code-projects E-Commerce Website 1.0 allows attackers to manipulate database queries through the supp_id parameter...

Oct 9, 2025
CVE-2025-11507
7.3

This SQL injection vulnerability in PHPGurukul Beauty Parlour Management System 1.1 allows remote attackers to execute arbitrary SQL commands through ...

Oct 8, 2025
CVE-2025-11505
7.3

This vulnerability allows remote attackers to execute SQL injection attacks via the 'delid' parameter in the /admin/new-appointment.php file of PHPGur...

Oct 8, 2025
CVE-2025-11503
7.3

This SQL injection vulnerability in PHPGurukul Beauty Parlour Management System 1.1 allows attackers to manipulate database queries through the 'delid...

Oct 8, 2025
CVE-2025-11488
7.3

This CVE describes a command injection vulnerability in D-Link DIR-852 routers that allows remote attackers to execute arbitrary commands on affected ...

Oct 8, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,170 CVEs classified as CWE-74, with 104 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free