CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,180
Total CVEs
107
Critical
1,281
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
226
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,180)

CVE-2025-8983
7.3

This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows remote attackers to execute arbitrary SQL command...

Aug 14, 2025
CVE-2025-8981
7.3

This SQL injection vulnerability in Online Tour and Travel Management System 1.0 allows attackers to manipulate database queries through the payment_t...

Aug 14, 2025
CVE-2025-8972
7.3

This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows attackers to manipulate database queries through ...

Aug 14, 2025
CVE-2025-8971
7.3

This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows attackers to execute arbitrary SQL commands via t...

Aug 14, 2025
CVE-2025-8969
7.3

This SQL injection vulnerability in Online Tour and Travel Management System 1.0 allows attackers to manipulate database queries through the /admin/ap...

Aug 14, 2025
CVE-2025-8966
7.3

This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows attackers to execute arbitrary SQL commands via t...

Aug 14, 2025
CVE-2025-8955
7.3

This SQL injection vulnerability in PHPGurukul Hospital Management System 4.0 allows attackers to manipulate database queries through the docfees para...

Aug 14, 2025
CVE-2025-8954
7.3

This SQL injection vulnerability in PHPGurukul Hospital Management System 4.0 allows remote attackers to execute arbitrary SQL commands via the doctor...

Aug 14, 2025
CVE-2025-8952
7.3

This SQL injection vulnerability in Campcodes Online Flight Booking Management System 1.0 allows attackers to execute arbitrary SQL commands via the l...

Aug 14, 2025
CVE-2025-8950
7.3

CVE-2025-8950 is an SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 that allows remote attackers to execute arbitrar...

Aug 14, 2025
CVE-2025-8948
7.3

CVE-2025-8948 is an SQL injection vulnerability in Projectworlds Visitor Management System 1.0 that allows remote attackers to execute arbitrary SQL c...

Aug 14, 2025
CVE-2025-8946
7.3

CVE-2025-8946 is an SQL injection vulnerability in the Online Notes Sharing Platform 1.0 login.php file that allows attackers to manipulate database q...

Aug 14, 2025
CVE-2025-8936
7.3

CVE-2025-8936 is an SQL injection vulnerability in 1000 Projects Sales Management System 1.0 that allows attackers to execute arbitrary SQL commands v...

Aug 14, 2025
CVE-2025-8935
7.3

CVE-2025-8935 is an SQL injection vulnerability in 1000 Projects Sales Management System 1.0 that allows remote attackers to execute arbitrary SQL com...

Aug 14, 2025
CVE-2025-8932
7.3

This SQL injection vulnerability in 1000 Projects Sales Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'ssalescat' p...

Aug 14, 2025
CVE-2025-8811
7.3

A critical SQL injection vulnerability exists in Simple Art Gallery 1.0's /Admin/registration.php file, specifically in the 'fname' parameter. This al...

Aug 10, 2025
CVE-2025-8809
7.3

A critical SQL injection vulnerability in code-projects Online Medicine Guide 1.0 allows remote attackers to execute arbitrary SQL commands via the 'd...

Aug 10, 2025
CVE-2025-8773
7.3

This critical SQL injection vulnerability in Dinstar Monitoring Platform allows attackers to execute arbitrary SQL commands by manipulating the userBe...

Aug 9, 2025
CVE-2025-8752
7.3

This critical vulnerability in wangzhixuan's spring-shiro-training allows remote attackers to execute arbitrary commands through command injection in ...

Aug 9, 2025
CVE-2025-8502
7.3

A critical SQL injection vulnerability exists in the Online Medicine Guide 1.0 software, specifically in the /changepass.php file's 'ups' parameter. T...

Aug 3, 2025
CVE-2025-8498
7.3

CVE-2025-8498 is a SQL injection vulnerability in code-projects Online Medicine Guide 1.0 that allows remote attackers to execute arbitrary SQL comman...

Aug 3, 2025
CVE-2025-8496
7.3

This critical SQL injection vulnerability in projectworlds Online Admission System 1.0 allows remote attackers to execute arbitrary SQL commands via t...

Aug 3, 2025
CVE-2025-8494
7.3

This critical SQL injection vulnerability in Intern Membership Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

Aug 3, 2025
CVE-2025-8493
7.3

This critical SQL injection vulnerability in Intern Membership Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

Aug 2, 2025
CVE-2025-8471
7.3

This critical SQL injection vulnerability in projectworlds Online Admission System 1.0 allows attackers to manipulate database queries through the a_i...

Aug 2, 2025
CVE-2025-8469
7.3

A critical SQL injection vulnerability in SourceCodester Online Hotel Reservation System 1.0 allows remote attackers to execute arbitrary SQL commands...

Aug 2, 2025
CVE-2025-8467
7.3

CVE-2025-8467 is a critical SQL injection vulnerability in Wazifa System 1.0 that allows remote attackers to execute arbitrary SQL commands via the Us...

Aug 2, 2025
CVE-2025-8466
7.3

CVE-2025-8466 is a critical SQL injection vulnerability in code-projects Online Farm System 1.0 that allows remote attackers to execute arbitrary SQL ...

Aug 2, 2025
CVE-2025-8443
7.3

CVE-2025-8443 is a critical SQL injection vulnerability in the Online Medicine Guide 1.0 software that allows attackers to execute arbitrary SQL comma...

Aug 1, 2025
CVE-2025-8442
7.3

CVE-2025-8442 is a critical SQL injection vulnerability in Online Medicine Guide 1.0 that allows remote attackers to execute arbitrary SQL commands vi...

Aug 1, 2025
CVE-2025-8437
7.3

CVE-2025-8437 is a critical SQL injection vulnerability in Kitchen Treasure 1.0's userregistration.php file that allows remote attackers to manipulate...

Aug 1, 2025
CVE-2025-8439
7.3

A critical SQL injection vulnerability in code-projects Wazifa System 1.0 allows remote attackers to execute arbitrary SQL commands via the Password p...

Aug 1, 2025
CVE-2025-8436
7.3

CVE-2025-8436 is a critical SQL injection vulnerability in projectworlds Online Admission System 1.0 that allows remote attackers to execute arbitrary...

Aug 1, 2025
CVE-2025-8431
7.3

This critical SQL injection vulnerability in PHPGurukul Boat Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'boa...

Aug 1, 2025
CVE-2025-8407
7.3

CVE-2025-8407 is a critical SQL injection vulnerability in code-projects Vehicle Management 1.0 that allows remote attackers to execute arbitrary SQL ...

Jul 31, 2025
CVE-2025-8378
7.3

This critical SQL injection vulnerability in Campcodes Online Hotel Reservation System 1.0 allows attackers to manipulate database queries through the...

Jul 31, 2025
CVE-2025-8374
7.3

This critical SQL injection vulnerability in Vehicle Management 1.0 allows remote attackers to execute arbitrary SQL commands via the 'company' parame...

Jul 31, 2025
CVE-2025-8372
7.3

This is a critical SQL injection vulnerability in Exam Form Submission 1.0 that allows attackers to manipulate database queries through the 'credits' ...

Jul 31, 2025
CVE-2025-8371
7.3

This critical SQL injection vulnerability in Exam Form Submission 1.0 allows remote attackers to execute arbitrary SQL commands via the 'credits' para...

Jul 31, 2025
CVE-2025-8338
7.3

CVE-2025-8338 is a critical SQL injection vulnerability in projectworlds Online Admission System 1.0 that allows remote attackers to execute arbitrary...

Jul 31, 2025
CVE-2025-8336
7.3

A critical SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 allows remote attackers to execute arbitrary SQL commands...

Jul 30, 2025
CVE-2025-8332
7.3

This critical SQL injection vulnerability in Online Farm System 1.0 allows remote attackers to execute arbitrary SQL commands via the Username paramet...

Jul 30, 2025
CVE-2025-8330
7.3

CVE-2025-8330 is a critical SQL injection vulnerability in Vehicle Management 1.0 that allows remote attackers to execute arbitrary SQL commands via t...

Jul 30, 2025
CVE-2025-8329
7.3

A critical SQL injection vulnerability exists in code-projects Vehicle Management 1.0 through the 'company' parameter in /filter3.php. Attackers can r...

Jul 30, 2025
CVE-2025-8327
7.3

This critical SQL injection vulnerability in Exam Form Submission 1.0 allows attackers to manipulate database queries through the /admin/delete_s8.php...

Jul 30, 2025
CVE-2025-8326
7.3

This critical SQL injection vulnerability in Exam Form Submission 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter i...

Jul 30, 2025
CVE-2025-8274
7.3

A critical SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 allows remote attackers to execute arbitrary SQL commands...

Jul 28, 2025
CVE-2025-8273
7.3

A critical SQL injection vulnerability in Exam Form Submission 1.0 allows remote attackers to execute arbitrary SQL commands via the 'credits' paramet...

Jul 28, 2025
CVE-2025-8271
7.3

This critical SQL injection vulnerability in Exam Form Submission 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter i...

Jul 28, 2025
CVE-2025-8269
7.3

This critical SQL injection vulnerability in Exam Form Submission 1.0 allows attackers to execute arbitrary SQL commands via the ID parameter in /admi...

Jul 28, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,180 CVEs classified as CWE-74, with 107 rated critical and 1,281 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free