CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,228
Total CVEs
122
Critical
1,303
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
244
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,228)

CVE-2025-4713
7.3

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via th...

May 15, 2025
CVE-2025-4709
7.3

A critical SQL injection vulnerability exists in Campcodes Sales and Inventory System 1.0, specifically in the /pages/transaction_del.php file's ID pa...

May 15, 2025
CVE-2025-4711
7.3

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via th...

May 15, 2025
CVE-2025-4708
7.3

A critical SQL injection vulnerability exists in Campcodes Sales and Inventory System 1.0, specifically in the discount parameter of the /pages/sales_...

May 15, 2025
CVE-2025-4706
7.3

This critical SQL injection vulnerability in Projectworlds Online Examination System 1.0 allows attackers to manipulate database queries through the V...

May 15, 2025
CVE-2025-4705
7.3

This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System 1.13 allows remote attackers to execute arbitrary SQL comman...

May 15, 2025
CVE-2025-4703
7.3

This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System allows remote attackers to execute arbitrary SQL commands vi...

May 15, 2025
CVE-2025-4702
7.3

This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System allows attackers to execute arbitrary SQL commands by manipu...

May 15, 2025
CVE-2025-4698
7.3

A critical SQL injection vulnerability in PHPGurukul Directory Management System 2.0 allows remote attackers to execute arbitrary SQL commands via the...

May 15, 2025
CVE-2025-4697
7.3

A critical SQL injection vulnerability exists in PHPGurukul Directory Management System 2.0, specifically in the /admin/edit-directory.php file via th...

May 15, 2025
CVE-2025-4553
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the fromdate/todate parameters in the /admin/bwdates-reports-details....

May 12, 2025
CVE-2025-4550
7.3

This critical SQL injection vulnerability in PHPGurukul Apartment Visitors Management System 1.0 allows attackers to manipulate database queries throu...

May 11, 2025
CVE-2025-4548
7.3

A critical SQL injection vulnerability in Campcodes Online Food Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via the ...

May 11, 2025
CVE-2025-4543
7.3

This critical SQL injection vulnerability in LyLme Spage 2.1 allows remote attackers to execute arbitrary SQL commands via the 'sort' parameter in adm...

May 11, 2025
CVE-2025-4508
7.3

A critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the f...

May 10, 2025
CVE-2025-4506
7.3

This critical SQL injection vulnerability in Campcodes Online Food Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via t...

May 10, 2025
CVE-2025-4504
7.3

This critical SQL injection vulnerability in SourceCodester Online College Library System 1.0 allows attackers to manipulate database queries through ...

May 10, 2025
CVE-2025-4503
7.3

This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to manipulate database queries via the I...

May 10, 2025
CVE-2025-4492
7.3

This critical SQL injection vulnerability in Campcodes Online Food Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via t...

May 9, 2025
CVE-2025-4490
7.3

This critical SQL injection vulnerability in Campcodes Online Food Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via t...

May 9, 2025
CVE-2025-4486
7.3

This critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ...

May 9, 2025
CVE-2025-4488
7.3

CVE-2025-4488 is a critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 that allows remote attackers to execute arbitrary SQ...

May 9, 2025
CVE-2025-4484
7.3

This critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ...

May 9, 2025
CVE-2025-4482
7.3

A critical SQL injection vulnerability in Project Worlds Student Project Allocation System 1.0 allows remote attackers to execute arbitrary SQL comman...

May 9, 2025
CVE-2025-4481
7.3

This critical SQL injection vulnerability in SourceCodester Apartment Visitor Management System 1.0 allows remote attackers to execute arbitrary SQL c...

May 9, 2025
CVE-2025-4464
7.3

This critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 allows attackers to execute arbitrary SQL commands through the /aj...

May 9, 2025
CVE-2025-4466
7.3

CVE-2025-4466 is a critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 that allows remote attackers to execute arbitrary SQ...

May 9, 2025
CVE-2025-4457
7.3

A critical SQL injection vulnerability exists in Project Worlds Car Rental Project 1.0, specifically in the /admin/approve.php file's ID parameter. Th...

May 9, 2025
CVE-2025-4363
7.3

A critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'ri...

May 6, 2025
CVE-2025-4362
7.3

A critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the mem...

May 6, 2025
CVE-2025-4360
7.3

A critical SQL injection vulnerability exists in itsourcecode Gym Management System 1.0 through the /view_member.php file's ID parameter. Attackers ca...

May 6, 2025
CVE-2025-4358
7.3

A critical SQL injection vulnerability in PHPGurukul Company Visitor Management System 2.0 allows remote attackers to execute arbitrary SQL commands v...

May 6, 2025
CVE-2025-4331
7.3

This critical SQL injection vulnerability in SourceCodester Online Student Clearance System 1.0 allows attackers to execute arbitrary SQL commands via...

May 6, 2025
CVE-2025-4314
7.3

CVE-2025-4314 is a critical SQL injection vulnerability in SourceCodester Advanced Web Store 1.0 that allows attackers to execute arbitrary SQL comman...

May 6, 2025
CVE-2025-4309
7.3

This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.1 allows attackers to manipulate database queries through the ...

May 6, 2025
CVE-2025-4311
7.3

A critical SQL injection vulnerability in itsourcecode Content Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

May 6, 2025
CVE-2025-4307
7.3

This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.1 allows remote attackers to execute arbitrary SQL commands vi...

May 6, 2025
CVE-2025-4304
7.3

This critical SQL injection vulnerability in PHPGurukul Cyber Cafe Management System 1.0 allows attackers to manipulate database queries through the m...

May 6, 2025
CVE-2025-4301
7.3

A critical SQL injection vulnerability in itsourcecode Content Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

May 6, 2025
CVE-2025-4297
7.3

This critical SQL injection vulnerability in PHPGurukul Men Salon Management System 2.0 allows attackers to execute arbitrary SQL commands via the /ad...

May 5, 2025
CVE-2025-4266
7.3

This critical SQL injection vulnerability in PHPGurukul Notice Board System 1.0 allows attackers to execute arbitrary SQL commands via the fromdate/to...

May 5, 2025
CVE-2025-4264
7.3

A critical SQL injection vulnerability exists in PHPGurukul Emergency Ambulance Hiring Portal 1.0, specifically in the /admin/edit-ambulance.php file ...

May 5, 2025
CVE-2025-4262
7.3

This critical SQL injection vulnerability in PHPGurukul Online DJ Booking Management System 1.0 allows remote attackers to execute arbitrary SQL comma...

May 5, 2025
CVE-2025-4249
7.3

This critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 allows attackers to manipulate database queries through the /man...

May 4, 2025
CVE-2025-4242
7.3

This critical SQL injection vulnerability in PHPGurukul Online Birth Certificate System 2.0 allows attackers to manipulate database queries through th...

May 3, 2025
CVE-2025-4226
7.3

This critical SQL injection vulnerability in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 allows remote attackers to execute arbitrary SQL co...

May 3, 2025
CVE-2025-4214
7.3

This critical SQL injection vulnerability in PHPGuruku Online DJ Booking Management System 1.0 allows remote attackers to execute arbitrary SQL comman...

May 2, 2025
CVE-2025-4213
7.3

This critical SQL injection vulnerability in PHPGurukul Online Birth Certificate System 1.0 allows attackers to execute arbitrary SQL commands via the...

May 2, 2025
CVE-2025-4174
7.3

This critical vulnerability allows remote attackers to execute SQL injection attacks through the Username parameter in the /login.php file of PHPGuruk...

May 1, 2025
CVE-2025-4164
7.3

This critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.3 allows attackers to manipulate database queries via the ...

May 1, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,228 CVEs classified as CWE-74, with 122 rated critical and 1,303 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free