CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,231
Total CVEs
124
Critical
1,304
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,231)

CVE-2025-3309
7.3

CVE-2025-3309 is a critical SQL injection vulnerability in the Blood Bank Management System 1.0 that allows remote attackers to execute arbitrary SQL ...

Apr 6, 2025
CVE-2025-3307
7.3

This critical SQL injection vulnerability in Blood Bank Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the userem...

Apr 6, 2025
CVE-2025-3306
7.3

This critical SQL injection vulnerability in Blood Bank Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'fulln...

Apr 6, 2025
CVE-2025-3299
7.3

This critical SQL injection vulnerability in PHPGurukul Men Salon Management System 1.0 allows attackers to execute arbitrary SQL commands via the Nam...

Apr 5, 2025
CVE-2025-3258
7.3

A critical SQL injection vulnerability exists in PHPGurukul Old Age Home Management System 1.0 through the /search.php file's searchdata parameter. At...

Apr 4, 2025
CVE-2025-3239
7.3

This critical SQL injection vulnerability in PHPGurukul Online Fire Reporting System 1.2 allows remote attackers to execute arbitrary SQL commands via...

Apr 4, 2025
CVE-2025-3238
7.3

A critical SQL injection vulnerability exists in PHPGurukul Online Fire Reporting System 1.2, specifically in the /search-request.php file's searchdat...

Apr 4, 2025
CVE-2025-3231
7.3

This critical SQL injection vulnerability in PHPGurukul Zoo Management System 2.1 allows remote attackers to execute arbitrary SQL commands via the pa...

Apr 4, 2025
CVE-2025-3220
7.3

This critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 allows remote attackers to execute arbitrary SQL commands via th...

Apr 4, 2025
CVE-2025-3216
7.3

CVE-2025-3216 is a critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 that allows remote attackers to execute arbitrary ...

Apr 4, 2025
CVE-2025-3213
7.3

This critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 allows attackers to manipulate database queries through the rema...

Apr 4, 2025
CVE-2025-3195
7.3

A critical SQL injection vulnerability in itsourcecode Online Blood Bank Management System 1.0 allows remote attackers to execute arbitrary SQL comman...

Apr 4, 2025
CVE-2025-3188
7.3

This critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 allows attackers to manipulate database queries through the Cate...

Apr 4, 2025
CVE-2025-3186
7.3

This critical SQL injection vulnerability in Online Doctor Appointment Booking System 1.0 allows remote attackers to manipulate database queries throu...

Apr 4, 2025
CVE-2025-3184
7.3

This critical SQL injection vulnerability in Online Doctor Appointment Booking System 1.0 allows remote attackers to execute arbitrary SQL commands vi...

Apr 3, 2025
CVE-2025-3182
7.3

This critical SQL injection vulnerability in Online Doctor Appointment Booking System 1.0 allows attackers to execute arbitrary SQL commands via the '...

Apr 3, 2025
CVE-2025-3179
7.3

A critical SQL injection vulnerability exists in the Online Doctor Appointment Booking System 1.0, specifically in the /doctor/deletepatient.php file'...

Apr 3, 2025
CVE-2025-3176
7.3

This critical SQL injection vulnerability in Project Worlds Online Lawyer Management System 1.0 allows attackers to execute arbitrary SQL commands by ...

Apr 3, 2025
CVE-2025-3174
7.3

This critical SQL injection vulnerability in Project Worlds Online Lawyer Management System 1.0 allows remote attackers to execute arbitrary SQL comma...

Apr 3, 2025
CVE-2025-3170
7.3

A critical SQL injection vulnerability in Project Worlds Online Lawyer Management System 1.0 allows remote attackers to execute arbitrary SQL commands...

Apr 3, 2025
CVE-2025-3172
7.3

A critical SQL injection vulnerability exists in Project Worlds Online Lawyer Management System 1.0 via the unblock_id parameter in lawyer_booking.php...

Apr 3, 2025
CVE-2025-3168
7.3

This critical SQL injection vulnerability in PHPGurukul Time Table Generator System 1.0 allows remote attackers to execute arbitrary SQL commands via ...

Apr 3, 2025
CVE-2025-3151
7.3

This critical SQL injection vulnerability in SourceCodester Gym Management System 1.0 allows attackers to manipulate database queries through the user...

Apr 3, 2025
CVE-2025-3146
7.3

This critical SQL injection vulnerability in PHPGurukul Bus Pass Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'vie...

Apr 3, 2025
CVE-2025-3137
7.3

This critical SQL injection vulnerability in PHPGurukul Online Security Guards Hiring System 1.0 allows remote attackers to execute arbitrary SQL comm...

Apr 3, 2025
CVE-2025-3006
7.3

This critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 allows attackers to manipulate database queries through the Cate...

Mar 31, 2025
CVE-2025-2846
7.3

This critical SQL injection vulnerability in SourceCodester Online Eyewear Shop 1.0 allows attackers to execute arbitrary SQL commands through the reg...

Mar 27, 2025
CVE-2025-2740
7.3

A critical SQL injection vulnerability exists in PHPGurukul Old Age Home Management System 1.0, specifically in the /admin/eligibility.php file's page...

Mar 25, 2025
CVE-2025-2737
7.3

This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Mar 25, 2025
CVE-2025-2738
7.3

This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Mar 25, 2025
CVE-2025-2739
7.3

This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System 1.0 allows attackers to manipulate database queries through the...

Mar 25, 2025
CVE-2025-2734
7.3

This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System allows remote attackers to execute arbitrary SQL commands via t...

Mar 25, 2025
CVE-2025-2735
7.3

This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System allows attackers to execute arbitrary SQL commands through the ...

Mar 25, 2025
CVE-2025-2736
7.3

This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System allows attackers to manipulate database queries via the 'fromda...

Mar 25, 2025
CVE-2025-2683
7.3

This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to manipulate database queries via the mobi...

Mar 24, 2025
CVE-2025-2684
7.3

This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...

Mar 24, 2025
CVE-2025-2682
7.3

This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows remote attackers to manipulate database queries throu...

Mar 24, 2025
CVE-2025-2681
7.3

This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to manipulate database queries through the ...

Mar 24, 2025
CVE-2025-2679
7.3

This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...

Mar 24, 2025
CVE-2025-2680
7.3

This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to manipulate database queries through the ...

Mar 24, 2025
CVE-2025-2678
7.3

This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...

Mar 24, 2025
CVE-2025-2677
7.3

This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to manipulate database queries through the ...

Mar 24, 2025
CVE-2025-2676
7.3

This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...

Mar 24, 2025
CVE-2025-2675
7.3

This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to execute arbitrary SQL commands via the l...

Mar 24, 2025
CVE-2025-2674
7.3

This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to manipulate database queries through the ...

Mar 24, 2025
CVE-2025-2665
7.3

This critical SQL injection vulnerability in PHPGurukul Online Security Guards Hiring System 1.0 allows remote attackers to execute arbitrary SQL comm...

Mar 23, 2025
CVE-2025-2663
7.3

This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to execute arbitrary SQL commands via the s...

Mar 23, 2025
CVE-2025-2661
7.3

This critical SQL injection vulnerability in Project Worlds Online Time Table Generator 1.0 allows remote attackers to execute arbitrary SQL commands ...

Mar 23, 2025
CVE-2025-2659
7.3

This critical SQL injection vulnerability in Project Worlds Online Time Table Generator 1.0 allows remote attackers to execute arbitrary SQL commands ...

Mar 23, 2025
CVE-2025-2660
7.3

This critical SQL injection vulnerability in Project Worlds Online Time Table Generator 1.0 allows remote attackers to execute arbitrary SQL commands ...

Mar 23, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,231 CVEs classified as CWE-74, with 124 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free