CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,170
Total CVEs
104
Critical
1,277
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
221
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,170)

CVE-2025-11479
7.3

This SQL injection vulnerability in SourceCodester Wedding Reservation Management System 1.0 allows remote attackers to execute arbitrary SQL commands...

Oct 8, 2025
CVE-2025-11476
7.3

This SQL injection vulnerability in SourceCodester Simple E-Commerce Bookstore 1.0 allows attackers to manipulate database queries through the login_u...

Oct 8, 2025
CVE-2025-11475
7.3

Advanced Library Management System 1.0 contains a SQL injection vulnerability in the view_member.php file through the user_id parameter. Attackers can...

Oct 8, 2025
CVE-2025-11471
7.3

This SQL injection vulnerability in SourceCodester Hotel and Lodge Management System 1.0 allows attackers to manipulate database queries through the /...

Oct 8, 2025
CVE-2025-11473
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'currsymbol' parameter in the /edit_curr.php file of SourceCodest...

Oct 8, 2025
CVE-2025-11434
7.3

CVE-2025-11434 is an SQL injection vulnerability in itsourcecode Student Transcript Processing System 1.0 that allows attackers to manipulate database...

Oct 8, 2025
CVE-2025-11422
7.3

This vulnerability allows remote attackers to execute SQL injection attacks via the Username parameter in the /admin/login.php file of Campcodes Advan...

Oct 8, 2025
CVE-2025-11415
7.3

This vulnerability allows remote attackers to execute SQL injection attacks via the 'delid' parameter in the /admin/customer-list.php file of PHPGuruk...

Oct 7, 2025
CVE-2025-11397
7.3

An SQL injection vulnerability exists in SourceCodester Hotel and Lodge Management System 1.0's login.php file via the email parameter. This allows re...

Oct 7, 2025
CVE-2025-11396
7.3

This SQL injection vulnerability in Simple Food Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via the Category paramet...

Oct 7, 2025
CVE-2025-11349
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the searchdata parameter in /search-visitor.php in Campcodes Online A...

Oct 7, 2025
CVE-2025-11343
7.3

This vulnerability allows unauthenticated SQL injection in the Student Crud Operation 3.3 software via the delete.php file. Attackers can manipulate t...

Oct 6, 2025
CVE-2025-11334
7.3

Campcodes Online Apartment Visitor Management System 1.0 contains a SQL injection vulnerability in the /visitor-detail.php file through the editid par...

Oct 6, 2025
CVE-2025-11329
7.3

This SQL injection vulnerability in code-projects Online Course Registration 1.0 allows attackers to manipulate database queries through the ID parame...

Oct 6, 2025
CVE-2025-11316
7.3

This CVE describes a SQL injection vulnerability in Tipray's Data Leakage Prevention System version 1.0. Attackers can exploit the findCategoryPage.do...

Oct 6, 2025
CVE-2025-11314
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'sort' parameter in the findRolePage function of Tipray Data Leak...

Oct 6, 2025
CVE-2025-11315
7.3

This CVE describes a SQL injection vulnerability in Tipray's Data Leakage Prevention System version 1.0. Attackers can exploit the findUserPage.do end...

Oct 6, 2025
CVE-2025-11312
7.3

This CVE describes a SQL injection vulnerability in Tipray Data Leakage Prevention System 1.0. Attackers can remotely exploit the findModulePage.do en...

Oct 6, 2025
CVE-2025-11311
7.3

This SQL injection vulnerability in Tipray Data Leakage Prevention System allows attackers to execute arbitrary SQL commands by manipulating the 'sort...

Oct 6, 2025
CVE-2025-11309
7.3

This CVE describes a SQL injection vulnerability in Tipray Data Leakage Prevention System 1.0. Attackers can remotely exploit the 'sort' parameter in ...

Oct 5, 2025
CVE-2025-11115
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the starttime/endtime parameters in the /addtime.php file of Simple S...

Sep 28, 2025
CVE-2025-11111
7.3

This SQL injection vulnerability in Campcodes Advanced Online Voting Management System 1.0 allows attackers to manipulate database queries through the...

Sep 28, 2025
CVE-2025-11109
7.3

This SQL injection vulnerability in Campcodes Computer Sales and Inventory System 1.0 allows attackers to manipulate database queries through the /pag...

Sep 28, 2025
CVE-2025-11107
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'corcode' parameter in the /schedulingsystem/addcourse.php file i...

Sep 28, 2025
CVE-2025-11105
7.3

CVE-2025-11105 is an SQL injection vulnerability in code-projects Simple Scheduling System 1.0 affecting the /schedulingsystem/addsubject.php file. At...

Sep 28, 2025
CVE-2025-11101
7.3

CVE-2025-11101 is a SQL injection vulnerability in itsourcecode Open Source Job Portal 1.0 that allows remote attackers to execute arbitrary SQL comma...

Sep 28, 2025
CVE-2025-11094
7.3

This SQL injection vulnerability in code-projects E-Commerce Website 1.0 allows attackers to manipulate database queries through the prod_id parameter...

Sep 28, 2025
CVE-2025-11089
7.3

This CVE describes a SQL injection vulnerability in kidaze CourseSelectionSystem that allows remote attackers to execute arbitrary SQL commands via ma...

Sep 28, 2025
CVE-2025-11076
7.3

This SQL injection vulnerability in Campcodes Online Learning Management System 1.0 allows attackers to manipulate database queries through the depart...

Sep 27, 2025
CVE-2025-11074
7.3

This SQL injection vulnerability in Project Monitoring System 1.0 allows attackers to execute arbitrary SQL commands through the login form. Attackers...

Sep 27, 2025
CVE-2025-11070
7.3

Projectworlds Online Shopping System 1.0 contains a SQL injection vulnerability in the /store/cart_add.php file that allows remote attackers to execut...

Sep 27, 2025
CVE-2025-11064
7.3

This SQL injection vulnerability in Campcodes Online Learning Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'depart...

Sep 27, 2025
CVE-2025-11062
7.3

Campcodes Online Learning Management System 1.0 contains a SQL injection vulnerability in the /admin/save_student.php file via the class_id parameter....

Sep 27, 2025
CVE-2025-11057
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Pet Grooming Management Software 1.0 via the ID par...

Sep 27, 2025
CVE-2025-11055
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Online Hotel Reservation System 1.0 via the 'addres...

Sep 27, 2025
CVE-2025-11053
7.3

CVE-2025-11053 is a SQL injection vulnerability in PHPGurukul Small CRM 4.0's password reset function. Attackers can exploit the 'email' parameter in ...

Sep 27, 2025
CVE-2025-11052
7.3

CVE-2025-11052 is a SQL injection vulnerability in kidaze CourseSelectionSystem 1.0 that allows remote attackers to execute arbitrary SQL commands via...

Sep 27, 2025
CVE-2025-11045
7.3

This vulnerability allows remote attackers to execute arbitrary commands on WAYOS LQ series devices by manipulating the Name parameter in the /usb_pas...

Sep 26, 2025
CVE-2025-11039
7.3

Campcodes Computer Sales and Inventory System 1.0 contains a SQL injection vulnerability in the /pages/us_edit1.php file via the ID parameter. This al...

Sep 26, 2025
CVE-2025-11036
7.3

This SQL injection vulnerability in code-projects E-Commerce Website 1.0 allows remote attackers to execute arbitrary SQL commands via the user_id par...

Sep 26, 2025
CVE-2025-11032
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against kidaze CourseSelectionSystem by manipulating the CPU parameter in ...

Sep 26, 2025
CVE-2025-10973
7.3

This CVE describes a SQL injection vulnerability in the JackieDYH Resume-management-system's /admin/show.php file via the userid parameter. Attackers ...

Sep 25, 2025
CVE-2025-10967
7.3

This CVE describes a SQL injection vulnerability in MuFen-mker PHP-Usermm software affecting the /chkuser.php endpoint. Attackers can manipulate the U...

Sep 25, 2025
CVE-2025-10857
7.3

CVE-2025-10857 is an SQL injection vulnerability in Campcodes Point of Sale System POS 1.0 that allows attackers to manipulate database queries throug...

Sep 23, 2025
CVE-2025-10851
7.3

CVE-2025-10851 is an SQL injection vulnerability in Campcodes Gym Management System 1.0 that allows remote attackers to execute arbitrary SQL commands...

Sep 23, 2025
CVE-2025-10843
7.3

CVE-2025-10843 is an SQL injection vulnerability in Reservation Online Hotel Reservation System 1.0 that allows remote attackers to execute arbitrary ...

Sep 23, 2025
CVE-2025-10841
7.3

This SQL injection vulnerability in code-projects Online Bidding System 1.0 allows attackers to manipulate database queries through the ID parameter i...

Sep 23, 2025
CVE-2025-10836
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Pet Grooming Management Software 1.0 via the ID par...

Sep 23, 2025
CVE-2025-10833
7.3

CVE-2025-10833 is an SQL injection vulnerability in the 1000projects Bookstore Management System 1.0 login.php file that allows remote attackers to ex...

Sep 23, 2025
CVE-2025-10829
7.3

Campcodes Computer Sales and Inventory System 1.0 contains a SQL injection vulnerability in the /pages/sup_edit1.php file through manipulation of the ...

Sep 23, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,170 CVEs classified as CWE-74, with 104 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free