CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,264
Total CVEs
133
Critical
1,328
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 88
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,264)

CVE-2026-1419
4.7

This CVE describes a command injection vulnerability in D-Link DCS700l IP cameras running firmware version 1.03.09. Attackers can remotely execute arb...

Jan 26, 2026
CVE-2026-1064
4.7

This vulnerability allows remote attackers to execute arbitrary commands on Bastillion systems through command injection in the System Management Modu...

Jan 17, 2026
CVE-2026-1063
4.7

This CVE describes a command injection vulnerability in Bastillion's Public Key Management System that allows remote attackers to execute arbitrary co...

Jan 17, 2026
CVE-2026-0850
4.7

This CVE describes a SQL injection vulnerability in code-projects Intern Membership Management System 1.0. Attackers can exploit the activity_id param...

Jan 11, 2026
CVE-2026-0701
4.7

This SQL injection vulnerability in Intern Membership Management System 1.0 allows attackers to manipulate database queries through the Username param...

Jan 8, 2026
CVE-2026-0699
4.7

This SQL injection vulnerability in Intern Membership Management System 1.0 allows attackers to manipulate database queries through the activity_id pa...

Jan 8, 2026
CVE-2026-0698
4.7

This SQL injection vulnerability in Intern Membership Management System 1.0 allows remote attackers to manipulate database queries via the admin_id pa...

Jan 8, 2026
CVE-2026-0697
4.7

This CVE describes a SQL injection vulnerability in code-projects Intern Membership Management System 1.0. Attackers can remotely exploit the /intern/...

Jan 8, 2026
CVE-2025-15443
4.7

This SQL injection vulnerability in CRMEB allows attackers to manipulate database queries through the cate_id parameter in the product export endpoint...

Jan 4, 2026
CVE-2025-15442
4.7

This SQL injection vulnerability in CRMEB allows attackers to manipulate database queries through the cate_id parameter in the product export endpoint...

Jan 4, 2026
CVE-2023-7331
4.7

This CVE describes a SQL injection vulnerability in the User Handler component of PKrystian Full-Stack-Bank. Attackers can remotely exploit this vulne...

Dec 31, 2025
CVE-2025-15394
4.7

This vulnerability allows remote attackers to execute arbitrary code on iCMS systems through code injection in the configuration parameter handler. At...

Dec 31, 2025
CVE-2025-15169
4.7

This vulnerability allows remote attackers to execute SQL injection attacks against BiggiDroid Simple PHP CMS 1.0 by manipulating the ID parameter in ...

Dec 29, 2025
CVE-2025-15148
4.7

CVE-2025-15148 is a code injection vulnerability in CmsEasy's backend template management that allows attackers to execute arbitrary code by manipulat...

Dec 28, 2025
CVE-2025-15143
4.7

This SQL injection vulnerability in EyouCMS allows attackers to manipulate database queries through the backend template management component. It affe...

Dec 28, 2025
CVE-2025-15130
4.7

This vulnerability allows remote attackers to execute arbitrary code through the addPost function in SyCms's administrative panel. It affects all vers...

Dec 28, 2025
CVE-2025-15003
4.7

This vulnerability allows remote attackers to execute SQL injection attacks against SeaCMS versions up to 13.3 through manipulation of the e_id parame...

Dec 22, 2025
CVE-2025-14966
4.7

This SQL injection vulnerability in FastAdmin's Backend Controller allows attackers to execute arbitrary SQL commands by manipulating the custom/searc...

Dec 19, 2025
CVE-2025-14939
4.7

This SQL injection vulnerability in Online Appointment Booking System 1.0 allows attackers to manipulate database queries through the managername para...

Dec 19, 2025
CVE-2025-14899
4.7

This SQL injection vulnerability in CodeAstro Real Estate Management System 1.0 allows attackers to manipulate database queries through the /admin/sta...

Dec 19, 2025
CVE-2025-14900
4.7

CVE-2025-14900 is an SQL injection vulnerability in CodeAstro Real Estate Management System 1.0 that allows attackers to manipulate database queries v...

Dec 19, 2025
CVE-2025-14898
4.7

CVE-2025-14898 is an SQL injection vulnerability in CodeAstro Real Estate Management System 1.0 that allows attackers to execute arbitrary SQL command...

Dec 19, 2025
CVE-2025-14897
4.7

This SQL injection vulnerability in CodeAstro Real Estate Management System 1.0 allows attackers to execute arbitrary SQL commands via the /admin/user...

Dec 19, 2025
CVE-2025-14837
4.7

This vulnerability in ZZCMS 2025 allows remote attackers to inject malicious code through the 'icp' parameter in the backend site configuration module...

Dec 18, 2025
CVE-2025-14729
4.7

This vulnerability allows remote attackers to execute arbitrary code on CTCMS Content Management System installations through code injection in the ba...

Dec 15, 2025
CVE-2025-14730
4.7

This vulnerability allows remote attackers to execute arbitrary code on CTCMS Content Management System installations up to version 2.1.2. The flaw ex...

Dec 15, 2025
CVE-2025-14694
4.7

This CVE describes a SQL injection vulnerability in ketr JEPaaS versions up to 7.2.8. Attackers can remotely exploit the readAllPostil function by man...

Dec 15, 2025
CVE-2025-14648
4.7

This vulnerability allows remote attackers to execute arbitrary commands on DedeBIZ systems through command injection in the catalog_add.php file. Att...

Dec 14, 2025
CVE-2025-14229
4.7

This CSV injection vulnerability in SourceCodester Inventory Management System 1.0 allows attackers to inject malicious formulas into exported CSV fil...

Dec 8, 2025
CVE-2025-14090
4.7

This vulnerability allows remote attackers to execute SQL injection attacks against AMTT Hotel Broadband Operation System 1.0 by manipulating the ID p...

Dec 5, 2025
CVE-2025-14011
4.7

This SQL injection vulnerability in JIZHICMS allows remote attackers to manipulate database queries through the aid/tid parameters in the comment func...

Dec 4, 2025
CVE-2025-14012
4.7

This SQL injection vulnerability in JIZHICMS allows attackers to execute arbitrary SQL commands through the batch comment deletion functionality. Atta...

Dec 4, 2025
CVE-2025-13586
4.7

This SQL injection vulnerability in SourceCodester Online Student Clearance System 1.0 allows attackers to manipulate database queries through the pas...

Nov 24, 2025
CVE-2025-13424
4.7

Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/add_product.php file via the txtProductName parameter. T...

Nov 20, 2025
CVE-2025-13302
4.7

CVE-2025-13302 is an SQL injection vulnerability in code-projects Courier Management System 1.0 that allows attackers to manipulate database queries t...

Nov 17, 2025
CVE-2025-13075
4.7

CVE-2025-13075 is an SQL injection vulnerability in Responsive Hotel Site 1.0's admin/usersettingdel.php file that allows attackers to manipulate data...

Nov 12, 2025
CVE-2025-13076
4.7

CVE-2025-13076 is an SQL injection vulnerability in Responsive Hotel Site 1.0 that allows remote attackers to execute arbitrary SQL commands via the '...

Nov 12, 2025
CVE-2025-12932
4.7

This SQL injection vulnerability in SourceCodester Baby Care System 1.0 allows attackers to manipulate database queries through the msgid parameter in...

Nov 10, 2025
CVE-2025-12914
4.7

This SQL injection vulnerability in aaPanel BaoTa's backend allows attackers to manipulate database queries through the /database?action=GetDatabaseAc...

Nov 8, 2025
CVE-2025-12913
4.7

CVE-2025-12913 is a SQL injection vulnerability in Responsive Hotel Site 1.0 that allows remote attackers to manipulate database queries through the I...

Nov 8, 2025
CVE-2025-12873
4.7

This SQL injection vulnerability in Campcodes School File Management 1.0 allows attackers to manipulate database queries through the user_id parameter...

Nov 7, 2025
CVE-2025-12860
4.7

This CVE describes an SQL injection vulnerability in DedeBIZ content management system. Attackers can manipulate the 'orderby' parameter in /admin/fre...

Nov 7, 2025
CVE-2025-12859
4.7

This vulnerability allows remote attackers to execute SQL injection attacks against DedeBIZ content management systems through the /admin/templets_one...

Nov 7, 2025
CVE-2025-12855
4.7

CVE-2025-12855 is an SQL injection vulnerability in Responsive Hotel Site 1.0's newsletterdel.php admin file. Attackers can manipulate the 'eid' param...

Nov 7, 2025
CVE-2025-12856
4.7

CVE-2025-12856 is a SQL injection vulnerability in Responsive Hotel Site 1.0's reservation.php admin endpoint. Attackers can manipulate the email para...

Nov 7, 2025
CVE-2025-12857
4.7

CVE-2025-12857 is an SQL injection vulnerability in Responsive Hotel Site 1.0's roombook.php admin file that allows attackers to manipulate database q...

Nov 7, 2025
CVE-2025-12853
4.7

This SQL injection vulnerability in SourceCodester Best House Rental Management System 1.0 allows attackers to manipulate database queries through the...

Nov 7, 2025
CVE-2025-12610
4.7

CodeAstro Gym Management System 1.0 contains a SQL injection vulnerability in the /admin/view-progress-report.php file through manipulation of the ID ...

Nov 3, 2025
CVE-2025-12594
4.7

This SQL injection vulnerability in Simple Online Hotel Reservation System 2.0 allows attackers to manipulate database queries through the Name parame...

Nov 2, 2025
CVE-2025-12314
4.7

This vulnerability is an SQL injection flaw in the Food Ordering System 1.0 by code-projects, specifically in the /admin/deleteitem.php file via the i...

Oct 27, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,264 CVEs classified as CWE-74, with 133 rated critical and 1,328 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free