CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,241
Total CVEs
129
Critical
1,309
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,241)

CVE-2025-7189
6.3

A critical SQL injection vulnerability exists in code-projects Chat System 1.0 through the /user/send_message.php file's msg parameter. Attackers can ...

Jul 8, 2025
CVE-2025-7187
6.3

CVE-2025-7187 is a critical SQL injection vulnerability in code-projects Chat System 1.0 that allows remote attackers to execute arbitrary SQL command...

Jul 8, 2025
CVE-2025-7167
6.3

This critical SQL injection vulnerability in Responsive Blog Site 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter i...

Jul 8, 2025
CVE-2025-7162
6.3

This critical SQL injection vulnerability in PHPGurukul Zoo Management System 2.1 allows remote attackers to execute arbitrary SQL commands via the 'c...

Jul 8, 2025
CVE-2025-7159
6.3

This critical SQL injection vulnerability in PHPGurukul Zoo Management System 2.1 allows attackers to manipulate database queries through the ID param...

Jul 8, 2025
CVE-2025-7156
6.3

CVE-2025-7156 is a critical SQL injection vulnerability in hitsz-ids airda version 0.0.3 that allows remote attackers to execute arbitrary SQL command...

Jul 8, 2025
CVE-2025-7149
6.3

This critical SQL injection vulnerability in Campcodes Advanced Online Voting System 1.0 allows remote attackers to execute arbitrary SQL commands via...

Jul 7, 2025
CVE-2025-7125
6.3

A critical SQL injection vulnerability exists in the itsourcecode Employee Management System up to version 1.0. Attackers can remotely exploit this vu...

Jul 7, 2025
CVE-2025-7101
6.3

This critical vulnerability in BoyunCMS allows remote attackers to execute arbitrary code by manipulating the db_pass parameter during installation. I...

Jul 7, 2025
CVE-2025-6915
6.3

A critical SQL injection vulnerability exists in PHPGurukul Student Record System 3.2's /register.php file, allowing remote attackers to manipulate da...

Jun 30, 2025
CVE-2025-6913
6.3

A critical SQL injection vulnerability exists in PHPGurukul Student Record System 3.2 through the /admin-profile.php file's aemailid parameter. This a...

Jun 30, 2025
CVE-2025-6911
6.3

This critical SQL injection vulnerability in PHPGurukul Student Record System 3.2 allows attackers to execute arbitrary SQL commands via the 'del' par...

Jun 30, 2025
CVE-2025-6909
6.3

This CVE describes a critical SQL injection vulnerability in PHPGurukul Old Age Home Management System 1.0. Attackers can remotely exploit the /admin/...

Jun 30, 2025
CVE-2025-6884
6.3

A critical SQL injection vulnerability exists in code-projects Staff Audit System 1.0 through the /search_index.php file's Search parameter. This allo...

Jun 30, 2025
CVE-2025-6879
6.3

This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows attackers to manipulate database queries through t...

Jun 30, 2025
CVE-2025-6877
6.3

This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows remote attackers to execute arbitrary SQL commands...

Jun 30, 2025
CVE-2025-6875
6.3

This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows remote attackers to execute arbitrary SQL commands...

Jun 29, 2025
CVE-2025-6862
6.3

This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows remote attackers to execute arbitrary SQL commands...

Jun 29, 2025
CVE-2025-6860
6.3

This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows remote attackers to execute arbitrary SQL commands...

Jun 29, 2025
CVE-2025-6850
6.3

CVE-2025-6850 is a critical SQL injection vulnerability in Simple Forum 1.0 that allows remote attackers to execute arbitrary SQL commands via the 'Fi...

Jun 29, 2025
CVE-2025-6847
6.3

A critical SQL injection vulnerability exists in Simple Forum 1.0's /forum_edit.php file, allowing remote attackers to manipulate database queries via...

Jun 29, 2025
CVE-2025-6768
6.3

This critical SQL injection vulnerability in sfturing hosp_order allows remote attackers to execute arbitrary SQL commands by manipulating the hospita...

Jun 27, 2025
CVE-2025-6766
6.3

This critical SQL injection vulnerability in sfturing hosp_order allows remote attackers to execute arbitrary SQL commands by manipulating the offices...

Jun 27, 2025
CVE-2025-6753
6.3

This critical SQL injection vulnerability in huija bicycleSharingServer 1.0 allows remote attackers to execute arbitrary SQL commands through the sele...

Jun 27, 2025
CVE-2025-6749
6.3

This critical SQL injection vulnerability in huija bicycleSharingServer allows attackers to execute arbitrary SQL commands through the Title parameter...

Jun 27, 2025
CVE-2025-6609
6.3

This is a critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0. Attackers can remotely exploit the /panel/bwdates-r...

Jun 25, 2025
CVE-2025-6605
6.3

This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows remote attackers to execute arbitrary SQL commands...

Jun 25, 2025
CVE-2025-6607
6.3

This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows attackers to manipulate database queries through t...

Jun 25, 2025
CVE-2025-6417
6.3

This CVE describes a critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.1. Attackers can exploit the 'awarddetails' pa...

Jun 21, 2025
CVE-2025-6415
6.3

This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System allows remote attackers to execute arbitrary SQL commands via th...

Jun 21, 2025
CVE-2025-6413
6.3

This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System allows remote attackers to execute arbitrary SQL commands via th...

Jun 21, 2025
CVE-2025-6411
6.3

This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.1 allows remote attackers to execute arbitrary SQL commands vi...

Jun 21, 2025
CVE-2025-6351
6.3

A critical SQL injection vulnerability exists in itsourcecode Employee Record Management System 1.0 through the /editprofile.php file. Attackers can r...

Jun 20, 2025
CVE-2025-6346
6.3

This vulnerability allows remote attackers to execute SQL injection attacks against the Advance Charity Management System 1.0 by manipulating the 'm06...

Jun 20, 2025
CVE-2025-6333
6.3

This critical SQL injection vulnerability in PHPGurukul Directory Management System 2.0 allows remote attackers to execute arbitrary SQL commands via ...

Jun 20, 2025
CVE-2025-6320
6.3

This critical SQL injection vulnerability in PHPGurukul Pre-School Enrollment System 1.0 allows attackers to manipulate database queries through the c...

Jun 20, 2025
CVE-2025-6319
6.3

A critical SQL injection vulnerability exists in PHPGurukul Pre-School Enrollment System 1.0, specifically in the /admin/add-teacher.php file's tsubje...

Jun 20, 2025
CVE-2025-6308
6.3

A critical SQL injection vulnerability in PHPGurukul Emergency Ambulance Hiring Portal 1.0 allows remote attackers to execute arbitrary SQL commands v...

Jun 20, 2025
CVE-2025-6276
6.3

This CVE describes a critical SQL injection vulnerability in the Brilliance Golden Link Secondary System. Attackers can exploit the 'custTradeName' pa...

Jun 19, 2025
CVE-2025-6267
6.3

This critical SQL injection vulnerability in zhilink ADP Application Developer Platform 1.0.0 allows remote attackers to execute arbitrary SQL command...

Jun 19, 2025
CVE-2025-6135
6.3

This critical SQL injection vulnerability in Projectworlds Life Insurance Management System 1.0 allows attackers to manipulate database queries throug...

Jun 16, 2025
CVE-2025-6133
6.3

This critical SQL injection vulnerability in Projectworlds Life Insurance Management System 1.0 allows attackers to execute arbitrary SQL commands via...

Jun 16, 2025
CVE-2025-6100
6.3

This critical SQL injection vulnerability in realguoshuai open-video-cms 1.0 allows remote attackers to execute arbitrary SQL commands via the 'sort' ...

Jun 16, 2025
CVE-2025-5859
6.3

This critical SQL injection vulnerability in PHPGurukul Nipah Virus Testing Management System 1.0 allows remote attackers to execute arbitrary SQL com...

Jun 9, 2025
CVE-2025-5857
6.3

This critical SQL injection vulnerability in Patient Record Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the it...

Jun 9, 2025
CVE-2025-5837
6.3

A critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.3 allows remote attackers to execute arbitrary SQL commands v...

Jun 7, 2025
CVE-2025-5784
6.3

This critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.3 allows remote attackers to execute arbitrary SQL command...

Jun 6, 2025
CVE-2025-5779
6.3

This critical SQL injection vulnerability in Patient Record Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the it...

Jun 6, 2025
CVE-2025-5782
6.3

This critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.3 allows attackers to manipulate database queries through ...

Jun 6, 2025
CVE-2025-5762
6.3

A critical SQL injection vulnerability exists in code-projects Patient Record Management System 1.0, specifically in the view_hematology.php file's it...

Jun 6, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,241 CVEs classified as CWE-74, with 129 rated critical and 1,309 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free