CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,158
Total CVEs
102
Critical
1,268
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
219
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,158)

CVE-2023-29213
9.0

CVE-2023-29213 is a server-side template injection vulnerability in XWiki Platform's logging UI component that allows remote code execution. Attackers...

Apr 17, 2023
CVE-2023-1287
9.0

This vulnerability allows remote attackers to execute arbitrary code on ENOVIA Live Collaboration servers by exploiting an XSL template injection flaw...

Mar 9, 2023
CVE-2025-15137
8.8

This vulnerability allows remote attackers to execute arbitrary commands on TRENDnet TEW-800MB routers through command injection in the NTPSyncWithHos...

Dec 28, 2025
CVE-2025-15136
8.8

This vulnerability allows remote attackers to execute arbitrary commands on TRENDnet TEW-800MB routers by injecting malicious commands through the man...

Dec 28, 2025
CVE-2025-14659
8.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-860LB1 and DIR-868LB1 routers by injecting malicious commands i...

Dec 14, 2025
CVE-2024-56835
8.8

A code injection vulnerability in the DHCP Server configuration file of Siemens RUGGEDCOM ROX devices allows attackers to execute arbitrary code. This...

Dec 9, 2025
CVE-2025-14107
8.8

This CVE describes a command injection vulnerability in ZSPACE Q2C NAS devices that allows remote attackers to execute arbitrary commands on affected ...

Dec 5, 2025
CVE-2025-14108
8.8

This vulnerability allows remote attackers to execute arbitrary commands on ZSPACE Q2C NAS devices by exploiting a command injection flaw in the file ...

Dec 5, 2025
CVE-2025-14106
8.8

This vulnerability allows remote attackers to execute arbitrary commands on ZSPACE Q2C NAS devices by injecting malicious input into the safe_dir para...

Dec 5, 2025
CVE-2025-4350
8.8

A critical command injection vulnerability in D-Link DIR-600L routers allows remote attackers to execute arbitrary commands by manipulating the wake_o...

May 6, 2025
CVE-2025-24962
8.8

CVE-2025-24962 is a command injection vulnerability in reNgine's nmap_cmd parameter that allows authenticated users to execute arbitrary commands on t...

Feb 3, 2025
CVE-2024-47180
8.8

Shields.io versions before server-2024-09-25 contain a remote code execution vulnerability in the JSONPath library used by dynamic badges. Attackers c...

Sep 26, 2024
CVE-2023-51939
8.8

A vulnerability in the cp_bbs_sig function of Relic relic-toolkit 0.6.0 allows remote attackers to extract sensitive information through fault injecti...

Feb 1, 2024
CVE-2024-23828
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on Nginx-UI servers via CRLF injection when modifying test_config_cmd ...

Jan 29, 2024
CVE-2024-23648
8.8

This vulnerability in Pimcore's Admin Classic Bundle allows attackers to perform account takeover by manipulating password reset emails. Attackers can...

Jan 24, 2024
CVE-2023-49964
8.8

This vulnerability allows attackers to perform Server-Side Template Injection (SSTI) attacks in Hyland Alfresco Community Edition by inserting malicio...

Dec 11, 2023
CVE-2023-48830
8.8

Shuttle Booking Software 2.0 contains a CSV injection vulnerability in the Languages export functionality. This allows attackers to inject malicious f...

Dec 7, 2023
CVE-2023-48835
8.8

Car Rental Script v3.0 contains a CSV injection vulnerability in the Language > Labels > Export functionality. This allows attackers to inject malicio...

Dec 7, 2023
CVE-2023-48826
8.8

Time Slots Booking Calendar 4.0 contains a CSV injection vulnerability in the unique ID field of the Reservations List. This allows attackers to injec...

Dec 7, 2023
CVE-2023-22522
8.8

This is a template injection vulnerability in Confluence Data Center and Server that allows authenticated attackers (including anonymous users) to inj...

Dec 6, 2023
CVE-2023-43835
8.8

This vulnerability allows authenticated attackers to inject arbitrary PHP code into the config.inc.php file of Super Store Finder, leading to remote c...

Oct 2, 2023
CVE-2023-34203
8.8

This vulnerability allows any authenticated user in Progress OpenEdge Management or OpenEdge Explorer to perform URL injection attacks to escalate pri...

Jun 23, 2023
CVE-2022-43769
8.8

This vulnerability allows attackers to inject Spring Expression Language templates through certain web services in Pentaho Business Analytics Server, ...

Apr 3, 2023
CVE-2022-22360
8.8

CVE-2022-22360 is an LDAP injection vulnerability in IBM Sterling Partner Engagement Manager that allows authenticated remote attackers to manipulate ...

Jul 19, 2022
CVE-2022-31593
8.8

CVE-2022-31593 is a code injection vulnerability in SAP Business One client version 10.0 that allows authenticated attackers with low privileges to ex...

Jul 12, 2022
CVE-2022-33011
8.8

CVE-2022-33011 is a host header injection vulnerability in Known CMS that allows attackers to perform account takeover by manipulating password reset ...

Jul 8, 2022
CVE-2022-31086
8.8

LDAP Account Manager versions before 8.0 contain a vulnerability where incorrect regular expressions allow uploading PHP scripts to the config/templat...

Jun 27, 2022
CVE-2022-23064
8.8

CVE-2022-23064 is a host header injection vulnerability in Snipe-IT that allows attackers to send password reset links pointing to attacker-controlled...

May 2, 2022
CVE-2021-41282
8.8

CVE-2021-41282 is a command injection vulnerability in pfSense's diag_routes.php that allows authenticated users to inject sed commands and write arbi...

Mar 1, 2022
CVE-2022-23616
8.8

CVE-2022-23616 allows unprivileged users to execute arbitrary code on XWiki Platform instances by injecting Groovy scripts into their profiles and tri...

Feb 9, 2022
CVE-2022-23614
8.8

CVE-2022-23614 is a code injection vulnerability in Twig's sandbox mode that allows attackers to execute arbitrary PHP functions when using the sort f...

Feb 4, 2022
CVE-2021-39031
8.8

This LDAP injection vulnerability in IBM WebSphere Application Server - Liberty allows authenticated remote attackers to manipulate LDAP queries throu...

Jan 25, 2022
CVE-2021-32649
8.8

October CMS versions before 1.0.473 and 1.1.6 contain a vulnerability where authenticated backend users with 'create, modify and delete website pages'...

Jan 14, 2022
CVE-2021-43852
8.8

CVE-2021-43852 is a prototype pollution vulnerability in OroPlatform that allows attackers to inject malicious properties into JavaScript prototypes v...

Jan 4, 2022
CVE-2021-41314
8.8

This vulnerability allows unauthenticated attackers to inject newline characters in the password field of NETGEAR smart switch web UIs, bypassing auth...

Sep 16, 2021
CVE-2021-32756
8.8

CVE-2021-32756 is a critical remote code execution vulnerability in ManageIQ's MiqExpression module where low-privilege users can inject and execute a...

Jul 21, 2021
CVE-2021-20574
8.8

CVE-2021-20574 is an LDAP injection vulnerability in IBM Security Identity Manager Adapters that allows authenticated attackers to execute malicious L...

Jun 28, 2021
CVE-2021-24002
8.8

This vulnerability allows attackers to inject arbitrary FTP commands by tricking users into clicking malicious FTP URLs containing encoded newline cha...

Jun 24, 2021
CVE-2021-30506
8.8

This vulnerability in Google Chrome for Android allowed attackers to inject malicious scripts or HTML into privileged pages by tricking users into ins...

Jun 4, 2021
CVE-2024-53860
8.6

This vulnerability in sp-php-email-handler allows attackers to specify arbitrary email recipients and inject user-provided content into confirmation e...

Nov 27, 2024
CVE-2021-29085
8.6

This vulnerability allows remote attackers to read arbitrary files on Synology DiskStation Manager (DSM) systems through improper input sanitization i...

Jun 23, 2021
CVE-2025-67733
8.5

This vulnerability in Valkey allows malicious users to inject arbitrary data into response streams via scripting commands, potentially corrupting or t...

Feb 23, 2026
CVE-2025-32390
8.5

EspoCRM versions before 9.0.8 contain an HTML injection vulnerability in Knowledge Base articles that allows authenticated users with read access to c...

May 12, 2025
CVE-2025-24904
8.5

CVE-2025-24904 is a vulnerability in libsignal-service-rs that allows servers or malicious clients to inject plaintext content envelopes, potentially ...

Feb 13, 2025
CVE-2023-29521
8.4

CVE-2023-29521 is a critical remote code execution vulnerability in XWiki Platform where any user with view rights can execute arbitrary Groovy, Pytho...

Apr 19, 2023
CVE-2021-43837
8.4

CVE-2021-43837 is a remote code execution vulnerability in vault-cli where secrets starting with '!template!' are interpreted as Jinja2 templates. Att...

Dec 16, 2021
CVE-2024-39906
8.3

This CVE describes a command injection vulnerability in Haven blog's IndieAuth functionality that allows authenticated attackers to execute arbitrary ...

Jul 19, 2024
CVE-2024-23830
8.3

CVE-2024-23830 is an account hijack vulnerability in MantisBT where an unauthenticated attacker can take over user accounts by poisoning password rese...

Feb 20, 2024
CVE-2025-64741
8.1

An improper authorization vulnerability in Zoom Workplace for Android allows unauthenticated attackers with network access to escalate privileges. Thi...

Nov 13, 2025
CVE-2025-61773
8.1

This vulnerability in pyLoad allows attackers to inject malicious content into the web interface due to insufficient input validation in the Captcha s...

Oct 9, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,158 CVEs classified as CWE-74, with 102 rated critical and 1,268 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free