CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,188
Total CVEs
109
Critical
1,287
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
227
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,188)

CVE-2025-7514
7.3

CVE-2025-7514 is a critical SQL injection vulnerability in Modern Bag 1.0 that allows remote attackers to execute arbitrary SQL commands via the idSta...

Jul 13, 2025
CVE-2025-7512
7.3

CVE-2025-7512 is a critical SQL injection vulnerability in Modern Bag 1.0 that allows remote attackers to execute arbitrary SQL commands via the conta...

Jul 13, 2025
CVE-2025-7510
7.3

This critical SQL injection vulnerability in Modern Bag 1.0 allows remote attackers to execute arbitrary SQL commands via the 'namepro' parameter in /...

Jul 13, 2025
CVE-2025-7508
7.3

CVE-2025-7508 is a critical SQL injection vulnerability in Modern Bag 1.0's admin/product-update.php file that allows remote attackers to manipulate d...

Jul 13, 2025
CVE-2025-7483
7.3

This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System 1.13 allows attackers to execute arbitrary SQL commands via ...

Jul 12, 2025
CVE-2025-7480
7.3

This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System allows attackers to manipulate database queries through the ...

Jul 12, 2025
CVE-2025-7478
7.3

CVE-2025-7478 is a critical SQL injection vulnerability in Modern Bag 1.0 that allows remote attackers to execute arbitrary SQL commands via the idCat...

Jul 12, 2025
CVE-2025-7475
7.3

A critical SQL injection vulnerability in Simple Car Rental System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'mpesa' param...

Jul 12, 2025
CVE-2025-7471
7.3

CVE-2025-7471 is a critical SQL injection vulnerability in Modern Bag 1.0 that allows remote attackers to execute arbitrary SQL commands via the user-...

Jul 12, 2025
CVE-2025-7469
7.3

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via th...

Jul 12, 2025
CVE-2025-7466
7.3

This critical SQL injection vulnerability in ABC Courier Management 1.0 allows remote attackers to execute arbitrary SQL commands via the Name paramet...

Jul 12, 2025
CVE-2025-7457
7.3

This critical SQL injection vulnerability in Campcodes Online Movie Theater Seat Reservation System 1.0 allows attackers to manipulate database querie...

Jul 11, 2025
CVE-2025-7455
7.3

This critical SQL injection vulnerability in Campcodes Online Movie Theater Seat Reservation System 1.0 allows remote attackers to execute arbitrary S...

Jul 11, 2025
CVE-2025-7454
7.3

A critical SQL injection vulnerability in Campcodes Online Movie Theater Seat Reservation System 1.0 allows remote attackers to execute arbitrary SQL ...

Jul 11, 2025
CVE-2025-7436
7.3

This critical SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 allows remote attackers to execute arbitrary SQL comma...

Jul 11, 2025
CVE-2025-7411
7.3

CVE-2025-7411 is a critical SQL injection vulnerability in LifeStyle Store 1.0 that allows remote attackers to execute arbitrary SQL commands via the ...

Jul 10, 2025
CVE-2025-7410
7.3

CVE-2025-7410 is a critical SQL injection vulnerability in LifeStyle Store 1.0 that allows remote attackers to execute arbitrary SQL commands via the ...

Jul 10, 2025
CVE-2025-7220
7.3

Campcodes Payroll Management System 1.0 contains a critical SQL injection vulnerability in the /ajax.php?action=save_deductions endpoint. Attackers ca...

Jul 9, 2025
CVE-2025-7218
7.3

CVE-2025-7218 is a critical SQL injection vulnerability in Campcodes Payroll Management System 1.0 that allows remote attackers to execute arbitrary S...

Jul 9, 2025
CVE-2025-7211
7.3

CVE-2025-7211 is a critical SQL injection vulnerability in LifeStyle Store 1.0 that allows remote attackers to execute arbitrary SQL commands via the ...

Jul 9, 2025
CVE-2025-7197
7.3

This critical SQL injection vulnerability in Jonnys Liquor 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in /admi...

Jul 8, 2025
CVE-2025-7193
7.3

This critical SQL injection vulnerability in Agri-Trading Online Shopping System allows remote attackers to execute arbitrary SQL commands through the...

Jul 8, 2025
CVE-2025-7191
7.3

This critical SQL injection vulnerability in the Student Enrollment System 1.0 allows attackers to manipulate database queries through the Username pa...

Jul 8, 2025
CVE-2025-7185
7.3

CVE-2025-7185 is a critical SQL injection vulnerability in code-projects Library System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Jul 8, 2025
CVE-2025-7183
7.3

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows attackers to execute arbitrary SQL commands through the C...

Jul 8, 2025
CVE-2025-7180
7.3

This critical SQL injection vulnerability in Staff Audit System 1.0 allows attackers to execute arbitrary SQL commands through the User parameter in /...

Jul 8, 2025
CVE-2025-7179
7.3

A critical SQL injection vulnerability in code-projects Library System 1.0 allows attackers to manipulate database queries through the Username parame...

Jul 8, 2025
CVE-2025-7176
7.3

This critical SQL injection vulnerability in PHPGurukul Hospital Management System 1.0 allows remote attackers to execute arbitrary SQL commands via t...

Jul 8, 2025
CVE-2025-7173
7.3

CVE-2025-7173 is a critical SQL injection vulnerability in code-projects Library System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Jul 8, 2025
CVE-2025-7170
7.3

A critical SQL injection vulnerability exists in the Crime Reporting System 1.0's registration.php file, allowing remote attackers to manipulate datab...

Jul 8, 2025
CVE-2025-7168
7.3

This critical SQL injection vulnerability in the Crime Reporting System 1.0 allows attackers to execute arbitrary SQL commands via the email parameter...

Jul 8, 2025
CVE-2025-7164
7.3

This critical SQL injection vulnerability in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 allows attackers to manipulate database queries thr...

Jul 8, 2025
CVE-2025-7160
7.3

This critical SQL injection vulnerability in PHPGurukul Zoo Management System 2.1 allows attackers to manipulate database queries through the Username...

Jul 8, 2025
CVE-2025-7157
7.3

CVE-2025-7157 is a critical SQL injection vulnerability in code-projects Online Note Sharing 1.0 that allows attackers to execute arbitrary SQL comman...

Jul 8, 2025
CVE-2025-7155
7.3

This critical vulnerability in PHPGurukul Online Notes Sharing System 1.0 allows remote attackers to perform SQL injection via the sessionid parameter...

Jul 8, 2025
CVE-2025-7147
7.3

This critical SQL injection vulnerability in CodeAstro Patient Record Management System 1.0 allows attackers to execute arbitrary SQL commands through...

Jul 7, 2025
CVE-2025-7136
7.3

This critical SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 allows remote attackers to execute arbitrary SQL comma...

Jul 7, 2025
CVE-2025-7134
7.3

A critical SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 allows remote attackers to execute arbitrary SQL commands...

Jul 7, 2025
CVE-2025-7132
7.3

Campcodes Payroll Management System 1.0 contains a critical SQL injection vulnerability in the /ajax.php?action=save_payroll endpoint via manipulation...

Jul 7, 2025
CVE-2025-7130
7.3

This critical SQL injection vulnerability in Campcodes Payroll Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

Jul 7, 2025
CVE-2025-7129
7.3

This critical SQL injection vulnerability in Campcodes Payroll Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

Jul 7, 2025
CVE-2025-7120
7.3

This critical SQL injection vulnerability in Campcodes Complaint Management System 1.0 allows attackers to manipulate database queries via the email p...

Jul 7, 2025
CVE-2025-7119
7.3

This critical SQL injection vulnerability in Campcodes Complaint Management System 1.0 allows attackers to execute arbitrary SQL commands via the User...

Jul 7, 2025
CVE-2025-6963
7.3

This critical SQL injection vulnerability in Campcodes Employee Management System 1.0 allows remote attackers to execute arbitrary SQL commands via th...

Jul 1, 2025
CVE-2025-6961
7.3

A critical SQL injection vulnerability exists in Campcodes Employee Management System 1.0, specifically in the /mark.php file's ID parameter. This all...

Jul 1, 2025
CVE-2025-6960
7.3

A critical SQL injection vulnerability in Campcodes Employee Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the I...

Jul 1, 2025
CVE-2025-6958
7.3

CVE-2025-6958 is a critical SQL injection vulnerability in Campcodes Employee Management System 1.0 that allows remote attackers to execute arbitrary ...

Jul 1, 2025
CVE-2025-6955
7.3

A critical SQL injection vulnerability in Campcodes Employee Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the '...

Jul 1, 2025
CVE-2025-6938
7.3

CVE-2025-6938 is a critical SQL injection vulnerability in Simple Pizza Ordering System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Jul 1, 2025
CVE-2025-6936
7.3

CVE-2025-6936 is a critical SQL injection vulnerability in Simple Pizza Ordering System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Jul 1, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,188 CVEs classified as CWE-74, with 109 rated critical and 1,287 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free