CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,214
Total CVEs
117
Critical
1,295
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
243
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,214)

CVE-2025-7147
7.3

This critical SQL injection vulnerability in CodeAstro Patient Record Management System 1.0 allows attackers to execute arbitrary SQL commands through...

Jul 7, 2025
CVE-2025-7136
7.3

This critical SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 allows remote attackers to execute arbitrary SQL comma...

Jul 7, 2025
CVE-2025-7134
7.3

A critical SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 allows remote attackers to execute arbitrary SQL commands...

Jul 7, 2025
CVE-2025-7132
7.3

Campcodes Payroll Management System 1.0 contains a critical SQL injection vulnerability in the /ajax.php?action=save_payroll endpoint via manipulation...

Jul 7, 2025
CVE-2025-7130
7.3

This critical SQL injection vulnerability in Campcodes Payroll Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

Jul 7, 2025
CVE-2025-7129
7.3

This critical SQL injection vulnerability in Campcodes Payroll Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

Jul 7, 2025
CVE-2025-7120
7.3

This critical SQL injection vulnerability in Campcodes Complaint Management System 1.0 allows attackers to manipulate database queries via the email p...

Jul 7, 2025
CVE-2025-7119
7.3

This critical SQL injection vulnerability in Campcodes Complaint Management System 1.0 allows attackers to execute arbitrary SQL commands via the User...

Jul 7, 2025
CVE-2025-6963
7.3

This critical SQL injection vulnerability in Campcodes Employee Management System 1.0 allows remote attackers to execute arbitrary SQL commands via th...

Jul 1, 2025
CVE-2025-6961
7.3

A critical SQL injection vulnerability exists in Campcodes Employee Management System 1.0, specifically in the /mark.php file's ID parameter. This all...

Jul 1, 2025
CVE-2025-6960
7.3

A critical SQL injection vulnerability in Campcodes Employee Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the I...

Jul 1, 2025
CVE-2025-6958
7.3

CVE-2025-6958 is a critical SQL injection vulnerability in Campcodes Employee Management System 1.0 that allows remote attackers to execute arbitrary ...

Jul 1, 2025
CVE-2025-6955
7.3

A critical SQL injection vulnerability in Campcodes Employee Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the '...

Jul 1, 2025
CVE-2025-6938
7.3

CVE-2025-6938 is a critical SQL injection vulnerability in Simple Pizza Ordering System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Jul 1, 2025
CVE-2025-6936
7.3

CVE-2025-6936 is a critical SQL injection vulnerability in Simple Pizza Ordering System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Jul 1, 2025
CVE-2025-6917
7.3

CVE-2025-6917 is a critical SQL injection vulnerability in Online Hotel Booking 1.0 that allows remote attackers to execute arbitrary SQL commands via...

Jun 30, 2025
CVE-2025-6907
7.3

A critical SQL injection vulnerability in code-projects Car Rental System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'fname...

Jun 30, 2025
CVE-2025-6905
7.3

A critical SQL injection vulnerability exists in code-projects Car Rental System 1.0 through the /signup.php file's fname parameter. Attackers can rem...

Jun 30, 2025
CVE-2025-6903
7.3

This is a critical SQL injection vulnerability in code-projects Car Rental System 1.0 that allows remote attackers to execute arbitrary SQL commands v...

Jun 30, 2025
CVE-2025-6902
7.3

This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Jun 30, 2025
CVE-2025-6891
7.3

A critical SQL injection vulnerability exists in code-projects Inventory Management System 1.0, specifically in the createUser.php file's Username par...

Jun 30, 2025
CVE-2025-6889
7.3

This critical SQL injection vulnerability in code-projects Movie Ticketing System 1.0 allows remote attackers to execute arbitrary SQL commands via th...

Jun 30, 2025
CVE-2025-6885
7.3

This critical SQL injection vulnerability in PHPGurukul Teachers Record Management System 2.1 allows attackers to manipulate database queries through ...

Jun 30, 2025
CVE-2025-6871
7.3

A critical SQL injection vulnerability in SourceCodester Simple Company Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ...

Jun 29, 2025
CVE-2025-6863
7.3

This critical SQL injection vulnerability in PHPGurukul Local Services Search Engine Management System allows remote attackers to execute arbitrary SQ...

Jun 29, 2025
CVE-2025-6845
7.3

CVE-2025-6845 is a critical SQL injection vulnerability in Simple Forum 1.0 that allows remote attackers to execute arbitrary SQL commands via the Use...

Jun 29, 2025
CVE-2025-6840
7.3

This critical SQL injection vulnerability in code-projects Product Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands thro...

Jun 29, 2025
CVE-2025-6836
7.3

A critical SQL injection vulnerability in code-projects Library System 1.0 allows remote attackers to execute arbitrary SQL commands via the phone par...

Jun 29, 2025
CVE-2025-6834
7.3

This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to manipulate database queries thro...

Jun 29, 2025
CVE-2025-6828
7.3

This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows attackers to manipulate database queries through the...

Jun 28, 2025
CVE-2025-6823
7.3

This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Jun 28, 2025
CVE-2025-6821
7.3

CVE-2025-6821 is a critical SQL injection vulnerability in code-projects Inventory Management System 1.0 that allows remote attackers to execute arbit...

Jun 28, 2025
CVE-2025-6819
7.3

This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Jun 28, 2025
CVE-2025-6668
7.3

This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Jun 25, 2025
CVE-2025-6665
7.3

This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Jun 25, 2025
CVE-2025-6611
7.3

This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Jun 25, 2025
CVE-2025-6502
7.3

This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows attackers to manipulate database queries through the...

Jun 23, 2025
CVE-2025-6500
7.3

This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Jun 23, 2025
CVE-2025-6489
7.3

This critical SQL injection vulnerability in Agri-Trading Online Shopping System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

Jun 22, 2025
CVE-2025-6483
7.3

CVE-2025-6483 is a critical SQL injection vulnerability in Simple Pizza Ordering System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Jun 22, 2025
CVE-2025-6481
7.3

CVE-2025-6481 is a critical SQL injection vulnerability in Simple Pizza Ordering System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Jun 22, 2025
CVE-2025-6479
7.3

This critical SQL injection vulnerability in Simple Pizza Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'dayfr...

Jun 22, 2025
CVE-2025-6474
7.3

CVE-2025-6474 is a critical SQL injection vulnerability in code-projects Inventory Management System 1.0 that allows remote attackers to execute arbit...

Jun 22, 2025
CVE-2025-6471
7.3

A critical SQL injection vulnerability exists in code-projects Online Bidding System 1.0's administrator interface. Attackers can remotely exploit the...

Jun 22, 2025
CVE-2025-6469
7.3

CVE-2025-6469 is a critical SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary S...

Jun 22, 2025
CVE-2025-6467
7.3

CVE-2025-6467 is a critical SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary S...

Jun 22, 2025
CVE-2025-6457
7.3

This critical SQL injection vulnerability in code-projects Online Hotel Reservation System 1.0 allows remote attackers to execute arbitrary SQL comman...

Jun 22, 2025
CVE-2025-6455
7.3

A critical SQL injection vulnerability exists in code-projects Online Hotel Reservation System 1.0. Attackers can remotely exploit the /messageexec.ph...

Jun 22, 2025
CVE-2025-6451
7.3

This critical SQL injection vulnerability in Simple Online Hotel Reservation System 1.0 allows remote attackers to execute arbitrary SQL commands via ...

Jun 22, 2025
CVE-2025-6449
7.3

This critical SQL injection vulnerability in Simple Online Hotel Reservation System 1.0 allows attackers to manipulate database queries via the transa...

Jun 22, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,214 CVEs classified as CWE-74, with 117 rated critical and 1,295 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free