CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,173
Total CVEs
106
Critical
1,277
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
222
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,173)

CVE-2025-10104
7.3

This SQL injection vulnerability in code-projects Online Event Judging System 1.0 allows attackers to manipulate database queries through the txtsearc...

Sep 8, 2025
CVE-2025-10102
7.3

CVE-2025-10102 is a SQL injection vulnerability in code-projects Online Event Judging System 1.0 that allows remote attackers to execute arbitrary SQL...

Sep 8, 2025
CVE-2025-10100
7.3

This SQL injection vulnerability in SourceCodester Simple Forum Discussion System 1.0 allows attackers to execute arbitrary SQL commands via the Usern...

Sep 8, 2025
CVE-2025-10090
7.3

This CVE describes a SQL injection vulnerability in Jinher OA software up to version 1.2, specifically in the GetTreeDate.aspx file. Attackers can man...

Sep 8, 2025
CVE-2025-10082
7.3

CVE-2025-10082 is an SQL injection vulnerability in SourceCodester Online Polling System 1.0 that allows remote attackers to execute arbitrary SQL com...

Sep 8, 2025
CVE-2025-10078
7.3

This SQL injection vulnerability in SourceCodester Online Polling System 1.0 allows attackers to manipulate database queries through the ID parameter ...

Sep 8, 2025
CVE-2025-10076
7.3

This SQL injection vulnerability in SourceCodester Online Polling System 1.0 allows attackers to manipulate database queries through the email paramet...

Sep 8, 2025
CVE-2025-10068
7.3

CVE-2025-10068 is a SQL injection vulnerability in itsourcecode Online Discussion Forum 1.0 that allows remote attackers to execute arbitrary SQL comm...

Sep 7, 2025
CVE-2025-10062
7.3

CVE-2025-10062 is an SQL injection vulnerability in itsourcecode Student Information Management System 1.0 that allows attackers to manipulate databas...

Sep 6, 2025
CVE-2025-10033
7.3

CVE-2025-10033 is an SQL injection vulnerability in itsourcecode Online Discussion Forum 1.0 that allows attackers to manipulate database queries thro...

Sep 6, 2025
CVE-2025-10030
7.3

CVE-2025-10030 is a SQL injection vulnerability in Campcodes Grocery Sales and Inventory System 1.0 that allows remote attackers to execute arbitrary ...

Sep 6, 2025
CVE-2025-10025
7.3

This SQL injection vulnerability in PHPGurukul Online Course Registration 3.1 allows attackers to manipulate database queries through the semester par...

Sep 5, 2025
CVE-2025-9935
7.3

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK N600R routers via command injection in the web interface. Attacke...

Sep 4, 2025
CVE-2025-9930
7.3

This SQL injection vulnerability in Beauty Parlour Management System 1.0 allows attackers to manipulate database queries through the mobnumber paramet...

Sep 4, 2025
CVE-2025-9932
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against PHPGurukul Beauty Parlour Management System 1.1 by manipulating th...

Sep 4, 2025
CVE-2025-9927
7.3

CVE-2025-9927 is a SQL injection vulnerability in projectworlds Travel Management System 1.0 that allows attackers to execute arbitrary SQL commands v...

Sep 3, 2025
CVE-2025-9926
7.3

CVE-2025-9926 is a SQL injection vulnerability in the Travel Management System 1.0 that allows remote attackers to execute arbitrary SQL commands via ...

Sep 3, 2025
CVE-2025-9924
7.3

CVE-2025-9924 is an SQL injection vulnerability in Travel Management System 1.0's enquiry.php file that allows attackers to manipulate database querie...

Sep 3, 2025
CVE-2025-9919
7.3

This SQL injection vulnerability in 1000projects Beauty Parlour Management System 1.0 allows attackers to manipulate database queries through the from...

Sep 3, 2025
CVE-2025-9839
7.3

CVE-2025-9839 is a SQL injection vulnerability in itsourcecode Student Information Management System 1.0 that allows attackers to execute arbitrary SQ...

Sep 2, 2025
CVE-2025-9837
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the studentId parameter in the Student Information Management System ...

Sep 2, 2025
CVE-2025-9832
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'phone' parameter in the /routers/register-router.php file of Sou...

Sep 2, 2025
CVE-2025-9811
7.3

This SQL injection vulnerability in Campcodes Farm Management System 1.0 allows attackers to manipulate database queries through the rating parameter ...

Sep 2, 2025
CVE-2025-9794
7.3

Campcodes Computer Sales and Inventory System 1.0 contains a SQL injection vulnerability in the /pages/pos_transac.php endpoint that allows remote att...

Sep 1, 2025
CVE-2025-9792
7.3

CVE-2025-9792 is an SQL injection vulnerability in itsourcecode Apartment Management System 1.0 that allows remote attackers to execute arbitrary SQL ...

Sep 1, 2025
CVE-2025-9789
7.3

This CVE describes a SQL injection vulnerability in SourceCodester Online Hotel Reservation System 1.0, specifically in the /admin/edituser.php file's...

Sep 1, 2025
CVE-2025-9786
7.3

This SQL injection vulnerability in Campcodes Online Learning Management System 1.0 allows attackers to manipulate database queries through the firstn...

Sep 1, 2025
CVE-2025-9770
7.3

CVE-2025-9770 is a SQL injection vulnerability in Campcodes Hospital Management System 1.0 that allows attackers to bypass authentication on the admin...

Sep 1, 2025
CVE-2025-9767
7.3

CVE-2025-9767 is an SQL injection vulnerability in itsourcecode Sports Management System 1.0 that allows remote attackers to execute arbitrary SQL com...

Sep 1, 2025
CVE-2025-9765
7.3

CVE-2025-9765 is an SQL injection vulnerability in itsourcecode Sports Management System 1.0 that allows remote attackers to execute arbitrary SQL com...

Sep 1, 2025
CVE-2025-9761
7.3

Campcodes Online Feeds Product Inventory System 1.0 contains a SQL injection vulnerability in the login component's username parameter. This allows re...

Sep 1, 2025
CVE-2025-9759
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'lastname' parameter in the Signup function of Campcodes/SourceCo...

Sep 1, 2025
CVE-2025-9757
7.3

This SQL injection vulnerability in Campcodes/SourceCodester Courier Management System 1.0 allows attackers to manipulate database queries through the...

Sep 1, 2025
CVE-2025-9751
7.3

CVE-2025-9751 is a SQL injection vulnerability in Campcodes Online Learning Management System 1.0 that allows remote attackers to execute arbitrary SQ...

Sep 1, 2025
CVE-2025-9750
7.3

CVE-2025-9750 is an SQL injection vulnerability in Campcodes Online Learning Management System 1.0 that allows remote attackers to execute arbitrary S...

Aug 31, 2025
CVE-2025-9743
7.3

This SQL injection vulnerability in code-projects Human Resource Integrated System 1.0 allows attackers to manipulate database queries through the log...

Aug 31, 2025
CVE-2025-9741
7.3

CVE-2025-9741 is an SQL injection vulnerability in code-projects Human Resource Integrated System 1.0 affecting the /login_query12.php file. Attackers...

Aug 31, 2025
CVE-2025-9739
7.3

Campcodes Online Water Billing System 1.0 contains a SQL injection vulnerability in the /process.php file's Username parameter. This allows remote att...

Aug 31, 2025
CVE-2025-9733
7.3

CVE-2025-9733 is a SQL injection vulnerability in code-projects Human Resource Integrated System 1.0 affecting the /login_timeee.php file via the emp_...

Aug 31, 2025
CVE-2025-9729
7.3

This SQL injection vulnerability in PHPGurukul Online Course Registration 3.1 allows attackers to manipulate database queries through the studentname ...

Aug 31, 2025
CVE-2025-9726
7.3

Campcodes Farm Management System 1.0 contains a SQL injection vulnerability in the /review.php file via the pid parameter. This allows remote attacker...

Aug 31, 2025
CVE-2025-9706
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Water Billing System 1.0 via the /edit.php file's I...

Aug 30, 2025
CVE-2025-9704
7.3

CVE-2025-9704 is a SQL injection vulnerability in SourceCodester Water Billing System 1.0 that allows remote attackers to execute arbitrary SQL comman...

Aug 30, 2025
CVE-2025-9701
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Simple Cafe Billing System 1.0 via the ID parameter...

Aug 30, 2025
CVE-2025-9699
7.3

This SQL injection vulnerability in SourceCodester Online Polling System 1.0 allows attackers to manipulate database queries through the myusername pa...

Aug 30, 2025
CVE-2025-9694
7.3

Campcodes Advanced Online Voting System 1.0 contains a SQL injection vulnerability in the admin login page that allows attackers to execute arbitrary ...

Aug 30, 2025
CVE-2025-9691
7.3

Campcodes Online Shopping System 1.0 contains a SQL injection vulnerability in the login.php file's Password parameter. Attackers can remotely exploit...

Aug 30, 2025
CVE-2025-9679
7.3

This SQL injection vulnerability in itsourcecode Student Information System 1.0 allows attackers to manipulate database queries through the ID paramet...

Aug 30, 2025
CVE-2025-9678
7.3

Campcodes Online Loan Management System 1.0 contains a SQL injection vulnerability in the delete_borrower function via the /ajax.php endpoint. Attacke...

Aug 29, 2025
CVE-2025-9669
7.3

CVE-2025-9669 is a SQL injection vulnerability in Jinher OA 1.0's GetTreeDate.aspx file that allows attackers to manipulate database queries via the I...

Aug 29, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,173 CVEs classified as CWE-74, with 106 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free