CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,264
Total CVEs
133
Critical
1,328
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 88
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,264)

CVE-2025-12315
4.7

This SQL injection vulnerability in code-projects Food Ordering System 1.0 allows attackers to manipulate database queries through the itemPrice param...

Oct 27, 2025
CVE-2025-12287
4.7

This SQL injection vulnerability in Bdtask Wholesale Inventory Control and Inventory Management System allows attackers to manipulate database queries...

Oct 27, 2025
CVE-2025-11944
4.7

This SQL injection vulnerability in Vvveb CMS allows attackers to execute arbitrary SQL commands through the Raw SQL Handler import function. It affec...

Oct 19, 2025
CVE-2025-11668
4.7

This SQL injection vulnerability in code-projects Automated Voting System 1.0 allows attackers to manipulate database queries through the Password par...

Oct 13, 2025
CVE-2025-11663
4.7

This SQL injection vulnerability in Campcodes Online Beauty Parlor Management System 1.0 allows attackers to manipulate database queries through the '...

Oct 13, 2025
CVE-2025-11595
4.7

This vulnerability allows SQL injection through the mobilenumber parameter in the /admin-profile.php file of Campcodes Online Apartment Visitor Manage...

Oct 11, 2025
CVE-2025-11342
4.7

CVE-2025-11342 is a SQL injection vulnerability in code-projects Online Course Registration 1.0 that allows attackers to manipulate database queries t...

Oct 6, 2025
CVE-2025-11073
4.7

This vulnerability allows remote attackers to execute arbitrary commands on Keyfactor RG-EW5100BE devices by injecting malicious commands through the ...

Sep 27, 2025
CVE-2025-10993
4.7

This vulnerability allows remote attackers to execute arbitrary code through template management functionality in MuYuCMS. It affects all installation...

Sep 26, 2025
CVE-2025-10662
4.7

This SQL injection vulnerability in SeaCMS allows attackers to manipulate database queries through the /admin_members.php endpoint. Attackers can pote...

Sep 18, 2025
CVE-2025-10394
4.7

This CVE describes a code injection vulnerability in the fcba_zzm ics-park Smart Park Management System 2.0, specifically in the Scheduled Task Module...

Sep 14, 2025
CVE-2025-10122
4.7

This SQL injection vulnerability in Maccms10 allows attackers to manipulate database queries through the 'where' parameter in the 'rep' function. Atta...

Sep 9, 2025
CVE-2025-10087
4.7

This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows attackers to manipulate database queries through the pr...

Sep 8, 2025
CVE-2025-9802
4.7

This SQL injection vulnerability in RemoteClinic 2.0 allows attackers to manipulate database queries through the ID parameter in /staff/profile.php. A...

Sep 2, 2025
CVE-2025-7127
4.7

This critical SQL injection vulnerability in the itsourcecode Employee Management System allows attackers to manipulate database queries through the c...

Jul 7, 2025
CVE-2025-7123
4.7

This critical SQL injection vulnerability in Campcodes Complaint Management System 1.0 allows remote attackers to execute arbitrary SQL commands via t...

Jul 7, 2025
CVE-2025-6869
4.7

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /admin/testimonials/manage.php file of Source...

Jun 29, 2025
CVE-2025-6867
4.7

CVE-2025-6867 is a critical SQL injection vulnerability in SourceCodester Simple Company Website 1.0 that allows remote attackers to execute arbitrary...

Jun 29, 2025
CVE-2025-6842
4.7

This SQL injection vulnerability in code-projects Product Inventory System 1.0 allows attackers to manipulate database queries through the ID paramete...

Jun 29, 2025
CVE-2025-6009
4.7

This is a critical SQL injection vulnerability in the like-girl software version 5.2.0. Attackers can remotely exploit the /admin/ipAddPost.php file b...

Jun 12, 2025
CVE-2025-6006
4.7

This critical SQL injection vulnerability in kiCode111 like-girl 5.2.0 allows remote attackers to execute arbitrary SQL commands via the /admin/ImgUpd...

Jun 12, 2025
CVE-2025-6008
4.7

This CVE describes a critical SQL injection vulnerability in kiCode111 like-girl version 5.2.0. Attackers can exploit the /admin/ImgAddPost.php file b...

Jun 12, 2025
CVE-2025-5207
4.7

This critical SQL injection vulnerability in SourceCodester Client Database Management System 1.0 allows attackers to execute arbitrary SQL commands v...

May 26, 2025
CVE-2025-5137
4.7

This CVE describes a critical code injection vulnerability in DedeCMS 5.7.117 that allows remote attackers to execute arbitrary code by manipulating t...

May 25, 2025
CVE-2025-20216
4.7

This vulnerability allows unauthenticated remote attackers to inject HTML content into authenticated users' browsers via the Cisco Catalyst SD-WAN Man...

May 7, 2025
CVE-2025-3797
4.7

This critical SQL injection vulnerability in SeaCMS allows remote attackers to execute arbitrary SQL commands via the e_id parameter in the /admin_top...

Apr 19, 2025
CVE-2025-3792
4.7

This critical SQL injection vulnerability in SeaCMS allows remote attackers to execute arbitrary SQL commands through the /admin_link.php endpoint. At...

Apr 18, 2025
CVE-2025-3563
4.7

This critical vulnerability in WuzhiCMS 4.1 allows remote attackers to execute arbitrary code through code injection in the Setting Handler component....

Apr 14, 2025
CVE-2025-2664
4.7

A critical SQL injection vulnerability exists in CodeZips Hospital Management System 1.0 via the /suadpeted.php file's ID parameter. This allows remot...

Mar 23, 2025
CVE-2025-2393
4.7

This critical vulnerability in code-projects Online Class and Exam Scheduling System 1.0 allows remote attackers to execute SQL injection attacks via ...

Mar 17, 2025
CVE-2025-2392
4.7

This critical SQL injection vulnerability in code-projects Online Class and Exam Scheduling System 1.0 allows remote attackers to execute arbitrary SQ...

Mar 17, 2025
CVE-2025-2132
4.7

This critical SQL injection vulnerability in ftcms 2.1 allows remote attackers to execute arbitrary SQL commands through the name parameter in the sea...

Mar 9, 2025
CVE-2025-2054
4.7

This critical SQL injection vulnerability in Blood Bank Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the state_...

Mar 7, 2025
CVE-2025-2044
4.7

This is a critical SQL injection vulnerability in code-projects Blood Bank Management System 1.0 that allows attackers to manipulate database queries ...

Mar 6, 2025
CVE-2025-2039
4.7

This critical SQL injection vulnerability in Blood Bank Management System 1.0 allows attackers to execute arbitrary SQL commands via the member_id par...

Mar 6, 2025
CVE-2025-1906
4.7

This critical SQL injection vulnerability in PHPGurukul Restaurant Table Booking System 1.0 allows attackers to manipulate database queries through th...

Mar 4, 2025
CVE-2025-1611
4.7

This vulnerability in ShopXO allows remote attackers to perform injection attacks through the template handler component. It affects all ShopXO instal...

Feb 24, 2025
CVE-2025-1173
4.7

This critical SQL injection vulnerability in 1000 Projects Bookstore Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Feb 11, 2025
CVE-2024-11956
4.7

This critical SQL injection vulnerability in Pimcore Customer Data Framework allows remote attackers to execute arbitrary SQL commands via the filterD...

Jan 28, 2025
CVE-2024-11659
4.7

This CVE describes a critical command injection vulnerability in EnGenius networking devices that allows remote attackers to execute arbitrary command...

Nov 25, 2024
CVE-2024-11657
4.7

This critical vulnerability allows remote attackers to execute arbitrary commands on affected EnGenius networking devices by injecting malicious input...

Nov 25, 2024
CVE-2024-11655
4.7

This critical vulnerability allows remote attackers to execute arbitrary commands on affected EnGenius networking devices by injecting malicious input...

Nov 25, 2024
CVE-2024-11654
4.7

This critical vulnerability in EnGenius wireless access points allows remote attackers to execute arbitrary commands via command injection in the trac...

Nov 25, 2024
CVE-2024-11652
4.7

This critical vulnerability in EnGenius networking devices allows remote attackers to execute arbitrary commands by manipulating the 'https_enable' pa...

Nov 25, 2024
CVE-2024-11213
4.7

This critical vulnerability in SourceCodester Best Employee Management System 1.0 allows authenticated attackers to perform SQL injection attacks via ...

Nov 14, 2024
CVE-2024-11058
4.7

This vulnerability allows remote attackers to execute SQL injection attacks against the Real Estate Management System by manipulating the 'id' paramet...

Nov 10, 2024
CVE-2024-10946
4.7

This is a SQL injection vulnerability in the Interlib Library Cluster Automation Management System that allows attackers to execute arbitrary SQL comm...

Nov 7, 2024
CVE-2026-1735
4.3

This CVE describes a command injection vulnerability in Yealink MeetingBar A30's Diagnostic Handler component. Attackers with physical access to the d...

Feb 2, 2026
CVE-2026-1154
4.3

This vulnerability allows attackers to inject malicious scripts into the E-Learning System's lesson module through Title/Description fields. When exec...

Jan 19, 2026
CVE-2025-67746
4.3

This CVE describes a vulnerability in Composer PHP dependency manager where attackers controlling remote package sources could inject ANSI control cha...

Dec 30, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,264 CVEs classified as CWE-74, with 133 rated critical and 1,328 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free