CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,170
Total CVEs
104
Critical
1,277
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
221
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,170)

CVE-2025-10831
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'prodcode' parameter in the /pages/pro_edit1.php file in Campcode...

Sep 23, 2025
CVE-2025-10812
7.3

This SQL injection vulnerability in Hostel Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in the...

Sep 22, 2025
CVE-2025-10811
7.3

CVE-2025-10811 is a SQL injection vulnerability in code-projects Hostel Management System 1.0 that allows attackers to manipulate database queries thr...

Sep 22, 2025
CVE-2025-10808
7.3

Campcodes Farm Management System 1.0 contains a SQL injection vulnerability in the /uploadProduct.php file via the Type parameter. This allows remote ...

Sep 22, 2025
CVE-2025-10802
7.3

CVE-2025-10802 is an SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Sep 22, 2025
CVE-2025-10800
7.3

CVE-2025-10800 is a SQL injection vulnerability in itsourcecode Online Discussion Forum 1.0 that allows remote attackers to execute arbitrary SQL comm...

Sep 22, 2025
CVE-2025-10798
7.3

This SQL injection vulnerability in code-projects Hostel Management System 1.0 allows attackers to manipulate database queries through the ID paramete...

Sep 22, 2025
CVE-2025-10796
7.3

This SQL injection vulnerability in Hostel Management System 1.0 allows attackers to manipulate database queries through the email parameter in the ad...

Sep 22, 2025
CVE-2025-10795
7.3

CVE-2025-10795 is an SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Sep 22, 2025
CVE-2025-10791
7.3

CVE-2025-10791 is a SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary SQL comma...

Sep 22, 2025
CVE-2025-10788
7.3

This vulnerability allows remote attackers to execute SQL injection attacks on SourceCodester Online Hotel Reservation System 1.0 via the deleteroomin...

Sep 22, 2025
CVE-2025-10786
7.3

This SQL injection vulnerability in Campcodes Grocery Sales and Inventory System 1.0 allows attackers to execute arbitrary SQL commands via the ID par...

Sep 22, 2025
CVE-2025-10784
7.3

Campcodes Online Learning Management System 1.0 contains a SQL injection vulnerability in the /admin/edit_subject.php file via the subject_code parame...

Sep 22, 2025
CVE-2025-10782
7.3

Campcodes Online Learning Management System 1.0 contains a SQL injection vulnerability in the /admin/class.php file via the class_name parameter. This...

Sep 22, 2025
CVE-2025-10781
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against Campcodes Online Learning Management System 1.0 through the /admin...

Sep 22, 2025
CVE-2025-10688
7.3

This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows remote attackers to execute arbitrary SQL commands via ...

Sep 18, 2025
CVE-2025-10687
7.3

This SQL injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows attackers to manipulate database queries through the Userna...

Sep 18, 2025
CVE-2025-10670
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against itsourcecode E-Logbook with Health Monitoring System for COVID-19 ...

Sep 18, 2025
CVE-2025-10668
7.3

CVE-2025-10668 is an SQL injection vulnerability in itsourcecode Online Discussion Forum 1.0 that allows remote attackers to execute arbitrary SQL com...

Sep 18, 2025
CVE-2025-10664
7.3

CVE-2025-10664 is a SQL injection vulnerability in PHPGurukul Small CRM 4.0 that allows remote attackers to execute arbitrary SQL commands via the 'su...

Sep 18, 2025
CVE-2025-10663
7.3

This SQL injection vulnerability in PHPGurukul Online Course Registration 3.1 allows attackers to manipulate database queries through the 'cgpa' param...

Sep 18, 2025
CVE-2025-10601
7.3

This SQL injection vulnerability in SourceCodester Online Exam Form Submission 1.0 allows attackers to manipulate database queries via the email param...

Sep 17, 2025
CVE-2025-10603
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against PHPGurukul Online Discussion Forum 1.0 through the search function...

Sep 17, 2025
CVE-2025-10597
7.3

This SQL injection vulnerability in kidaze CourseSelectionSystem allows remote attackers to execute arbitrary SQL commands by manipulating the 'cname'...

Sep 17, 2025
CVE-2025-10599
7.3

This CVE describes an SQL injection vulnerability in the itsourcecode Web-Based Internet Laboratory Management System 1.0. Attackers can manipulate th...

Sep 17, 2025
CVE-2025-10596
7.3

This CVE describes a SQL injection vulnerability in SourceCodester Online Exam Form Submission 1.0, specifically in the 'usn' parameter of /index.php....

Sep 17, 2025
CVE-2025-10565
7.3

Campcodes Grocery Sales and Inventory System 1.0 contains a SQL injection vulnerability in the /ajax.php?action=delete_receiving endpoint via manipula...

Sep 16, 2025
CVE-2025-10562
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /ajax.php?action=save_product endpoint in Cam...

Sep 16, 2025
CVE-2025-10482
7.3

This SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 allows attackers to execute arbitrary SQL commands via th...

Sep 15, 2025
CVE-2025-10479
7.3

CVE-2025-10479 is an SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 that allows remote attackers to execute a...

Sep 15, 2025
CVE-2025-10446
7.3

This SQL injection vulnerability in Campcodes Computer Sales and Inventory System 1.0 allows attackers to manipulate database queries through the /pag...

Sep 15, 2025
CVE-2025-10435
7.3

CVE-2025-10435 is a SQL injection vulnerability in Campcodes Computer Sales and Inventory System 1.0 that allows attackers to execute arbitrary SQL co...

Sep 15, 2025
CVE-2025-10426
7.3

CVE-2025-10426 is a SQL injection vulnerability in itsourcecode Online Laundry Management System 1.0 that allows remote attackers to execute arbitrary...

Sep 15, 2025
CVE-2025-10416
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /ajax.php?action=delete_supplier endpoint in ...

Sep 15, 2025
CVE-2025-10415
7.3

Campcodes Grocery Sales and Inventory System 1.0 contains a SQL injection vulnerability in the /ajax.php?action=save_supplier endpoint via manipulatio...

Sep 14, 2025
CVE-2025-10413
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against Campcodes Grocery Sales and Inventory System 1.0 via the /ajax.php...

Sep 14, 2025
CVE-2025-10405
7.3

CVE-2025-10405 is a SQL injection vulnerability in itsourcecode Baptism Information Management System 1.0 that allows remote attackers to execute arbi...

Sep 14, 2025
CVE-2025-10403
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against PHPGurukul Beauty Parlour Management System 1.1 by manipulating th...

Sep 14, 2025
CVE-2025-10402
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against PHPGurukul Beauty Parlour Management System 1.1 through the delid ...

Sep 14, 2025
CVE-2025-10396
7.3

This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows attackers to manipulate database queries through the ID...

Sep 14, 2025
CVE-2025-10324
7.3

This CVE describes a command injection vulnerability in Wavlink WL-WN578W2 routers that allows remote attackers to execute arbitrary commands on affec...

Sep 12, 2025
CVE-2025-10123
7.3

This CVE describes a command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands by manipula...

Sep 9, 2025
CVE-2025-10118
7.3

This CVE describes a SQL injection vulnerability in the itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. Attackers can exploit t...

Sep 9, 2025
CVE-2025-10115
7.3

CVE-2025-10115 is a SQL injection vulnerability in SiempreCMS that allows attackers to execute arbitrary SQL commands via the name/userName parameter ...

Sep 9, 2025
CVE-2025-10112
7.3

CVE-2025-10112 is a SQL injection vulnerability in itsourcecode Student Information Management System 1.0 that allows remote attackers to execute arbi...

Sep 9, 2025
CVE-2025-10109
7.3

Campcodes Online Loan Management System 1.0 contains a SQL injection vulnerability in the /ajax.php?action=delete_payment endpoint via manipulation of...

Sep 8, 2025
CVE-2025-10111
7.3

This SQL injection vulnerability in itsourcecode Student Information Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Sep 8, 2025
CVE-2025-10108
7.3

CVE-2025-10108 is an SQL injection vulnerability in Campcodes Online Loan Management System 1.0 that allows attackers to manipulate database queries v...

Sep 8, 2025
CVE-2025-10104
7.3

This SQL injection vulnerability in code-projects Online Event Judging System 1.0 allows attackers to manipulate database queries through the txtsearc...

Sep 8, 2025
CVE-2025-10102
7.3

CVE-2025-10102 is a SQL injection vulnerability in code-projects Online Event Judging System 1.0 that allows remote attackers to execute arbitrary SQL...

Sep 8, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,170 CVEs classified as CWE-74, with 104 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free