CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,165
Total CVEs
104
Critical
1,273
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
219
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,165)

CVE-2026-2220
7.3

CVE-2026-2220 is a SQL injection vulnerability in code-projects Online Reviewer System 1.0 that allows remote attackers to execute arbitrary SQL comma...

Feb 9, 2026
CVE-2026-2221
7.3

CVE-2026-2221 is a SQL injection vulnerability in code-projects Online Reviewer System 1.0 that allows remote attackers to execute arbitrary SQL comma...

Feb 9, 2026
CVE-2026-2217
7.3

This SQL injection vulnerability in itsourcecode Event Management System 1.0 allows attackers to execute arbitrary SQL commands via the ID parameter i...

Feb 9, 2026
CVE-2026-2211
7.3

This SQL injection vulnerability in code-projects Online Music Site 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter...

Feb 9, 2026
CVE-2026-2212
7.3

CVE-2026-2212 is a SQL injection vulnerability in code-projects Online Music Site 1.0 that allows remote attackers to execute arbitrary SQL commands v...

Feb 9, 2026
CVE-2026-2198
7.3

This SQL injection vulnerability in code-projects Online Reviewer System 1.0 allows attackers to manipulate database queries through the difficulty_id...

Feb 9, 2026
CVE-2026-2199
7.3

This CVE describes a SQL injection vulnerability in code-projects Online Reviewer System 1.0. Attackers can remotely exploit the user-delete.php file ...

Feb 9, 2026
CVE-2026-2196
7.3

This SQL injection vulnerability in code-projects Online Reviewer System 1.0 allows attackers to manipulate database queries through the test_id param...

Feb 9, 2026
CVE-2026-2197
7.3

This SQL injection vulnerability in code-projects Online Reviewer System 1.0 allows remote attackers to execute arbitrary SQL commands via the test_id...

Feb 9, 2026
CVE-2026-2195
7.3

This SQL injection vulnerability in code-projects Online Reviewer System 1.0 allows attackers to manipulate database queries through the ID parameter ...

Feb 9, 2026
CVE-2026-2190
7.3

CVE-2026-2190 is a SQL injection vulnerability in itsourcecode School Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Feb 8, 2026
CVE-2026-2189
7.3

CVE-2026-2189 is a SQL injection vulnerability in itsourcecode School Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Feb 8, 2026
CVE-2026-2172
7.3

This CVE describes a SQL injection vulnerability in code-projects Online Application System for Admission 1.0, specifically in the login endpoint at e...

Feb 8, 2026
CVE-2026-2173
7.3

CVE-2026-2173 is an SQL injection vulnerability in code-projects Online Examination System 1.0 that allows attackers to manipulate database queries th...

Feb 8, 2026
CVE-2026-2171
7.3

This SQL injection vulnerability in Online Student Management System 1.0 allows attackers to manipulate database queries through the login form. Attac...

Feb 8, 2026
CVE-2026-2166
7.3

This SQL injection vulnerability in code-projects Online Reviewer System 1.0 allows attackers to manipulate database queries through the login form. R...

Feb 8, 2026
CVE-2026-2161
7.3

This SQL injection vulnerability in itsourcecode Directory Management System 1.0 allows attackers to execute arbitrary SQL commands via the email para...

Feb 8, 2026
CVE-2026-2158
7.3

CVE-2026-2158 is a SQL injection vulnerability in code-projects Student Web Portal 1.0 that allows remote attackers to execute arbitrary SQL commands ...

Feb 8, 2026
CVE-2026-2136
7.3

CVE-2026-2136 is a SQL injection vulnerability in projectworlds Online Food Ordering System 1.0 that allows remote attackers to execute arbitrary SQL ...

Feb 8, 2026
CVE-2026-2132
7.3

This is a SQL injection vulnerability in code-projects Online Music Site 1.0 that allows remote attackers to execute arbitrary SQL commands via the tx...

Feb 8, 2026
CVE-2026-2116
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the expenses_id parameter in the /admin/edit_expenses.php file in its...

Feb 8, 2026
CVE-2026-2117
7.3

This is a SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows remote attackers to execute arbitrary SQL commands via...

Feb 8, 2026
CVE-2026-2115
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands on itsourcecode Society Management System 1.0 through the /admin/delete_e...

Feb 7, 2026
CVE-2026-2114
7.3

CVE-2026-2114 is an SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows attackers to manipulate database queries thr...

Feb 7, 2026
CVE-2026-2090
7.3

This SQL injection vulnerability in SourceCodester Online Class Record System 1.0 allows remote attackers to execute arbitrary SQL commands via the 't...

Feb 7, 2026
CVE-2026-2088
7.3

This SQL injection vulnerability in PHPGurukul Beauty Parlour Management System 1.1 allows attackers to manipulate database queries through the 'delid...

Feb 7, 2026
CVE-2026-2089
7.3

This SQL injection vulnerability in SourceCodester Online Class Record System 1.0 allows attackers to manipulate database queries through the ID param...

Feb 7, 2026
CVE-2026-2087
7.3

This SQL injection vulnerability in SourceCodester Online Class Record System 1.0 allows attackers to manipulate database queries through the user_ema...

Feb 7, 2026
CVE-2026-2083
7.3

This SQL injection vulnerability in code-projects Social Networking Site 1.0 allows attackers to manipulate database queries through the /delete_post....

Feb 7, 2026
CVE-2026-2073
7.3

CVE-2026-2073 is a SQL injection vulnerability in itsourcecode School Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Feb 7, 2026
CVE-2026-2060
7.3

This SQL injection vulnerability in Simple Blood Donor Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID para...

Feb 6, 2026
CVE-2026-2059
7.3

This SQL injection vulnerability in SourceCodester Medical Center Portal Management System 1.0 allows attackers to manipulate database queries through...

Feb 6, 2026
CVE-2026-2058
7.3

This CVE describes a SQL injection vulnerability in the CloudClassroom-PHP-Project software that allows remote attackers to execute arbitrary SQL comm...

Feb 6, 2026
CVE-2026-2057
7.3

This SQL injection vulnerability in SourceCodester Medical Center Portal Management System 1.0 allows attackers to execute arbitrary SQL commands via ...

Feb 6, 2026
CVE-2026-2018
7.3

CVE-2026-2018 is a SQL injection vulnerability in itsourcecode School Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Feb 6, 2026
CVE-2026-2014
7.3

CVE-2026-2014 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows attackers to manipulate database queries thro...

Feb 6, 2026
CVE-2026-2013
7.3

This SQL injection vulnerability in itsourcecode Student Management System 1.0 allows attackers to execute arbitrary SQL commands via the ID parameter...

Feb 6, 2026
CVE-2026-2011
7.3

This SQL injection vulnerability in itsourcecode Student Management System 1.0 allows attackers to execute arbitrary SQL commands through the /ramonsy...

Feb 6, 2026
CVE-2026-2012
7.3

CVE-2026-2012 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL com...

Feb 6, 2026
CVE-2026-1802
7.3

This CVE describes a command injection vulnerability in the Ziroom ZHOME A0101 router firmware version 1.0.1.0. Attackers can remotely execute arbitra...

Feb 3, 2026
CVE-2026-1701
7.3

CVE-2026-1701 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL co...

Jan 30, 2026
CVE-2026-1689
7.3

This CVE describes a remote command injection vulnerability in Tenda HG10 routers. Attackers can execute arbitrary commands on affected devices by man...

Jan 30, 2026
CVE-2026-1688
7.3

This SQL injection vulnerability in itsourcecode Directory Management System 1.0 allows attackers to execute arbitrary SQL commands via the Username p...

Jan 30, 2026
CVE-2026-1687
7.3

This CVE describes a command injection vulnerability in Tenda HG10 routers through the Boa webserver's formSamba endpoint. Attackers can remotely exec...

Jan 30, 2026
CVE-2026-1595
7.3

CVE-2026-1595 is an SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows remote attackers to execute arbitrary SQL co...

Jan 29, 2026
CVE-2026-1589
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against itsourcecode School Management System 1.0 via the txtsearch parame...

Jan 29, 2026
CVE-2026-1590
7.3

This SQL injection vulnerability in itsourcecode School Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID par...

Jan 29, 2026
CVE-2026-1593
7.3

CVE-2026-1593 is a SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows remote attackers to execute arbitrary SQL com...

Jan 29, 2026
CVE-2026-1594
7.3

This is an SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows attackers to execute arbitrary SQL commands through t...

Jan 29, 2026
CVE-2026-1545
7.3

CVE-2026-1545 is a SQL injection vulnerability in itsourcecode School Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Jan 28, 2026

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,165 CVEs classified as CWE-74, with 104 rated critical and 1,273 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free