CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,235
Total CVEs
128
Critical
1,304
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,235)

CVE-2025-13581
6.3

CVE-2025-13581 is an SQL injection vulnerability in itsourcecode Student Information System 1.0 that allows remote attackers to execute arbitrary SQL ...

Nov 24, 2025
CVE-2025-13579
6.3

This SQL injection vulnerability in code-projects Library System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in...

Nov 24, 2025
CVE-2025-13580
6.3

CVE-2025-13580 is a SQL injection vulnerability in code-projects Library System 1.0 affecting the /mail.php file. Attackers can remotely exploit this ...

Nov 24, 2025
CVE-2025-13575
6.3

This SQL injection vulnerability in code-projects Blog Site 1.0 allows attackers to manipulate database queries through the category_exists function. ...

Nov 24, 2025
CVE-2025-13571
6.3

This vulnerability allows remote attackers to execute SQL injection attacks against Simple Food Ordering System 1.0 by manipulating the ID parameter i...

Nov 23, 2025
CVE-2025-13570
6.3

This CVE describes a SQL injection vulnerability in the itsourcecode COVID Tracking System 1.0. Attackers can exploit this by manipulating the ID para...

Nov 23, 2025
CVE-2025-13568
6.3

CVE-2025-13568 is a SQL injection vulnerability in itsourcecode COVID Tracking System 1.0 that allows remote attackers to execute arbitrary SQL comman...

Nov 23, 2025
CVE-2025-13569
6.3

CVE-2025-13569 is an SQL injection vulnerability in itsourcecode COVID Tracking System 1.0 that allows attackers to manipulate database queries throug...

Nov 23, 2025
CVE-2025-13567
6.3

CVE-2025-13567 is a SQL injection vulnerability in itsourcecode COVID Tracking System 1.0 that allows remote attackers to execute arbitrary SQL comman...

Nov 23, 2025
CVE-2025-13546
6.3

This CVE describes a SQL injection vulnerability in the ashraf-kabir travel-agency software's search functionality. Attackers can remotely exploit the...

Nov 23, 2025
CVE-2025-13396
6.3

CVE-2025-13396 is a SQL injection vulnerability in code-projects Courier Management System 1.0 that allows attackers to manipulate database queries th...

Nov 19, 2025
CVE-2025-13346
6.3

This SQL injection vulnerability in SourceCodester Train Station Ticketing System 1.0 allows attackers to manipulate database queries via the /ajax.ph...

Nov 18, 2025
CVE-2025-13306
6.3

This CVE describes a command injection vulnerability in D-Link routers that allows attackers to execute arbitrary commands on affected devices by mani...

Nov 18, 2025
CVE-2025-13325
6.3

CVE-2025-13325 is a SQL injection vulnerability in itsourcecode Student Information System 1.0 that allows remote attackers to execute arbitrary SQL c...

Nov 18, 2025
CVE-2025-13303
6.3

This CVE describes a SQL injection vulnerability in the Courier Management System 1.0 by code-projects. Attackers can remotely exploit the /search-edi...

Nov 17, 2025
CVE-2025-13290
6.3

This SQL injection vulnerability in Simple Food Ordering System 1.0 allows attackers to manipulate database queries through the /saveorder.php endpoin...

Nov 17, 2025
CVE-2025-13289
6.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the SubCode parameter in the SubjectDetails.php file of the 1000proje...

Nov 17, 2025
CVE-2025-13287
6.3

CVE-2025-13287 is a SQL injection vulnerability in itsourcecode Online Voting System 1.0 that allows remote attackers to execute arbitrary SQL command...

Nov 17, 2025
CVE-2025-13286
6.3

CVE-2025-13286 is an SQL injection vulnerability in itsourcecode Online Voting System 1.0 that allows attackers to manipulate database queries through...

Nov 17, 2025
CVE-2025-13279
6.3

CVE-2025-13279 is an SQL injection vulnerability in Nero Social Networking Site 1.0 that allows remote attackers to execute arbitrary SQL commands via...

Nov 17, 2025
CVE-2025-13278
6.3

This SQL injection vulnerability in Advanced Library Management System 1.0 allows attackers to manipulate database queries through the datefrom/dateto...

Nov 17, 2025
CVE-2025-13274
6.3

Campcodes School Fees Payment Management System 1.0 contains a SQL injection vulnerability in the /ajax.php?action=delete_fees endpoint via the ID par...

Nov 17, 2025
CVE-2025-13273
6.3

CVE-2025-13273 is a SQL injection vulnerability in Campcodes School Fees Payment Management System 1.0 that allows remote attackers to execute arbitra...

Nov 17, 2025
CVE-2025-13268
6.3

This vulnerability allows remote attackers to execute injection attacks through the JDBC URL handler in Dromara dataCompare. The flaw exists in the Db...

Nov 17, 2025
CVE-2025-13269
6.3

This vulnerability allows remote attackers to execute SQL injection attacks against Campcodes School Fees Payment Management System 1.0 via the /ajax....

Nov 17, 2025
CVE-2025-13270
6.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /ajax.php?action=save_course endpoint in Camp...

Nov 17, 2025
CVE-2025-13267
6.3

This vulnerability allows remote attackers to execute SQL injection attacks against the Dental Clinic Appointment Reservation System 1.0 by manipulati...

Nov 17, 2025
CVE-2025-13264
6.3

This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Online Magazine Management System 1.0 via the ID pa...

Nov 17, 2025
CVE-2025-13263
6.3

This CVE describes an SQL injection vulnerability in SourceCodester Online Magazine Management System 1.0. Attackers can exploit the 'c' parameter in ...

Nov 17, 2025
CVE-2025-13260
6.3

Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the manufacturer/edit_product.php file via the cmbProductUnit param...

Nov 17, 2025
CVE-2025-13259
6.3

CVE-2025-13259 is a SQL injection vulnerability in Campcodes Supplier Management System 1.0 that allows attackers to execute arbitrary SQL commands vi...

Nov 17, 2025
CVE-2025-13256
6.3

This CVE describes a SQL injection vulnerability in the Advanced Library Management System 1.0 by projectworlds. Attackers can exploit the roll_number...

Nov 17, 2025
CVE-2025-13254
6.3

This SQL injection vulnerability in Advanced Library Management System 1.0 allows attackers to manipulate database queries through the roll_number par...

Nov 17, 2025
CVE-2025-13255
6.3

This SQL injection vulnerability in Advanced Library Management System 1.0 allows attackers to manipulate database queries through the book_search.php...

Nov 17, 2025
CVE-2025-13253
6.3

This SQL injection vulnerability in Advanced Library Management System 1.0 allows attackers to manipulate database queries through the Username parame...

Nov 17, 2025
CVE-2025-13251
6.3

This CVE describes a SQL injection vulnerability in WeiYe-Jing datax-web versions up to 2.1.2. Attackers can execute arbitrary SQL commands remotely, ...

Nov 16, 2025
CVE-2025-13243
6.3

This SQL injection vulnerability in code-projects Student Information System 2.0 allows attackers to execute arbitrary SQL commands through the /editp...

Nov 16, 2025
CVE-2025-13236
6.3

This SQL injection vulnerability in itsourcecode Inventory Management System 1.0 allows attackers to manipulate database queries through the ID parame...

Nov 16, 2025
CVE-2025-13234
6.3

This CVE describes a SQL injection vulnerability in itsourcecode Inventory Management System 1.0. Attackers can remotely exploit the /index.php?q=prod...

Nov 16, 2025
CVE-2025-13171
6.3

This SQL injection vulnerability in ZZCMS 2023 allows remote attackers to execute arbitrary SQL commands through the 'keyword' parameter in /admin/wan...

Nov 14, 2025
CVE-2025-13172
6.3

This CVE describes a SQL injection vulnerability in CodeAstro Gym Management System 1.0 that allows attackers to manipulate database queries through t...

Nov 14, 2025
CVE-2025-13168
6.3

This SQL injection vulnerability in ury-erp allows attackers to manipulate database queries through the search_term parameter in the overrided_past_or...

Nov 14, 2025
CVE-2025-13123
6.3

This CVE describes a SQL injection vulnerability in AMTT Hotel Broadband Operation System 1.0. Attackers can remotely exploit the /user/portal/get_fir...

Nov 13, 2025
CVE-2025-13059
6.3

This vulnerability allows remote attackers to execute arbitrary SQL commands on SourceCodester Alumni Management System 1.0 through SQL injection in t...

Nov 12, 2025
CVE-2025-13057
6.3

Campcodes School Fees Payment Management System 1.0 contains a SQL injection vulnerability in the /ajax.php?action=save_student endpoint via the ID pa...

Nov 12, 2025
CVE-2025-12926
6.3

This SQL injection vulnerability in SourceCodester Farm Management System 1.0 allows attackers to manipulate database queries through the /review.php ...

Nov 10, 2025
CVE-2025-12916
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Sangfor Operation and Maintenance Security Management System 3.0 through c...

Nov 9, 2025
CVE-2025-12329
6.3

This CVE describes an SQL injection vulnerability in shawon100 RUET OJ's /details.php file through manipulation of the ID parameter. Remote attackers ...

Oct 27, 2025
CVE-2025-12328
6.3

This SQL injection vulnerability in shawon100 RUET OJ allows attackers to manipulate database queries via the Name parameter in /contestproblem.php. A...

Oct 27, 2025
CVE-2025-12327
6.3

This SQL injection vulnerability in RUET OJ's /description.php file allows remote attackers to manipulate database queries via the ID parameter. It af...

Oct 27, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,235 CVEs classified as CWE-74, with 128 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free