CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,168
Total CVEs
104
Critical
1,275
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
220
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,168)

CVE-2026-1534
7.3

CVE-2026-1534 is a SQL injection vulnerability in code-projects Online Music Site 1.0 that allows remote attackers to execute arbitrary SQL commands v...

Jan 28, 2026
CVE-2026-1535
7.3

CVE-2026-1535 is a SQL injection vulnerability in code-projects Online Music Site 1.0 that allows remote attackers to execute arbitrary SQL commands v...

Jan 28, 2026
CVE-2026-1443
7.3

CVE-2026-1443 is a SQL injection vulnerability in code-projects Online Music Site 1.0 that allows remote attackers to execute arbitrary SQL commands v...

Jan 26, 2026
CVE-2026-1422
7.3

This SQL injection vulnerability in code-projects Online Examination System 1.0 allows attackers to manipulate database queries through the login page...

Jan 26, 2026
CVE-2026-1412
7.3

This CVE describes a command injection vulnerability in Sangfor Operation and Maintenance Security Management System. Attackers can execute arbitrary ...

Jan 26, 2026
CVE-2026-1192
7.3

This CVE describes a command injection vulnerability in Tosei Online Store Management System 1.01. Attackers can remotely execute arbitrary commands b...

Jan 19, 2026
CVE-2026-1179
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against Yonyou KSOA 9.0 systems by manipulating the 'folderid' parameter i...

Jan 19, 2026
CVE-2026-1177
7.3

This SQL injection vulnerability in Yonyou KSOA 9.0 allows remote attackers to execute arbitrary SQL commands via the folderid parameter in the /kmf/s...

Jan 19, 2026
CVE-2026-1178
7.3

This is a SQL injection vulnerability in Yonyou KSOA 9.0 that allows remote attackers to execute arbitrary SQL commands via the 'folderid' parameter i...

Jan 19, 2026
CVE-2026-1176
7.3

CVE-2026-1176 is a SQL injection vulnerability in itsourcecode School Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Jan 19, 2026
CVE-2026-1160
7.3

CVE-2026-1160 is a SQL injection vulnerability in PHPGurukul Directory Management System 1.0 that allows remote attackers to execute arbitrary SQL com...

Jan 19, 2026
CVE-2026-1159
7.3

CVE-2026-1159 is a SQL injection vulnerability in itsourcecode Online Frozen Foods Ordering System 1.0 that allows remote attackers to execute arbitra...

Jan 19, 2026
CVE-2026-1133
7.3

This CVE describes a SQL injection vulnerability in Yonyou KSOA 9.0 that allows remote attackers to execute arbitrary SQL commands via the 'folderid' ...

Jan 19, 2026
CVE-2026-1132
7.3

This CVE describes a SQL injection vulnerability in Yonyou KSOA 9.0 that allows remote attackers to execute arbitrary SQL commands via the folderid pa...

Jan 19, 2026
CVE-2026-1125
7.3

This CVE describes a remote command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary commands by manipulating the w...

Jan 18, 2026
CVE-2026-1123
7.3

This CVE describes a SQL injection vulnerability in Yonyou KSOA 9.0's /worksheet/work_mod.jsp file via the ID parameter in HTTP GET requests. Attacker...

Jan 18, 2026
CVE-2026-1120
7.3

This CVE describes a SQL injection vulnerability in Yonyou KSOA 9.0 that allows remote attackers to execute arbitrary SQL commands via the ID paramete...

Jan 18, 2026
CVE-2026-1121
7.3

This CVE describes a SQL injection vulnerability in Yonyou KSOA 9.0 that allows remote attackers to execute arbitrary SQL commands via the ID paramete...

Jan 18, 2026
CVE-2026-1122
7.3

This CVE describes a SQL injection vulnerability in Yonyou KSOA 9.0 that allows remote attackers to execute arbitrary SQL commands via the ID paramete...

Jan 18, 2026
CVE-2026-1119
7.3

This CVE describes a SQL injection vulnerability in itsourcecode Society Management System 1.0. Attackers can remotely exploit the /admin/delete_activ...

Jan 18, 2026
CVE-2026-1105
7.3

This SQL injection vulnerability in EasyCMS allows attackers to manipulate database queries through the _order parameter in /UserAction.class.php. Att...

Jan 18, 2026
CVE-2026-1059
7.3

This CVE describes a SQL injection vulnerability in FeMiner wms through commit 9cad1f1b179a98b9547fd003c23b07c7594775fa. Attackers can exploit the /sr...

Jan 17, 2026
CVE-2026-1050
7.3

This CVE describes a SQL injection vulnerability in risesoft-y9 Digital-Infrastructure's REST authentication endpoint. Attackers can remotely execute ...

Jan 17, 2026
CVE-2026-0852
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against code-projects Online Music Site 1.0 by manipulating the ID paramet...

Jan 12, 2026
CVE-2026-0851
7.3

This SQL injection vulnerability in code-projects Online Music Site 1.0 allows attackers to manipulate database queries through the txtusername parame...

Jan 12, 2026
CVE-2026-0700
7.3

This SQL injection vulnerability in Intern Membership Management System 1.0 allows attackers to execute arbitrary SQL commands through the Username pa...

Jan 8, 2026
CVE-2026-0607
7.3

CVE-2026-0607 is a SQL injection vulnerability in code-projects Online Music Site 1.0 that allows remote attackers to execute arbitrary SQL commands v...

Jan 6, 2026
CVE-2026-0606
7.3

CVE-2026-0606 is a SQL injection vulnerability in code-projects Online Music Site 1.0 that allows remote attackers to execute arbitrary SQL commands v...

Jan 5, 2026
CVE-2026-0605
7.3

CVE-2026-0605 is an SQL injection vulnerability in code-projects Online Music Site 1.0 that allows attackers to manipulate database queries through th...

Jan 5, 2026
CVE-2026-0583
7.3

This SQL injection vulnerability in code-projects Online Product Reservation System 1.0 allows attackers to manipulate database queries through the em...

Jan 5, 2026
CVE-2026-0579
7.3

This SQL injection vulnerability in code-projects Online Product Reservation System 1.0 allows attackers to manipulate database queries through the ad...

Jan 4, 2026
CVE-2026-0578
7.3

This SQL injection vulnerability in Online Product Reservation System 1.0 allows attackers to manipulate database queries through the /handgunner-admi...

Jan 4, 2026
CVE-2026-0576
7.3

This SQL injection vulnerability in code-projects Online Product Reservation System 1.0 allows remote attackers to execute arbitrary SQL commands thro...

Jan 4, 2026
CVE-2026-0575
7.3

This SQL injection vulnerability in code-projects Online Product Reservation System 1.0 allows attackers to manipulate database queries through the ad...

Jan 4, 2026
CVE-2026-0569
7.3

This SQL injection vulnerability in Online Music Site 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in /Frontend/...

Jan 2, 2026
CVE-2026-0570
7.3

CVE-2026-0570 is a SQL injection vulnerability in code-projects Online Music Site 1.0 that allows remote attackers to execute arbitrary SQL commands v...

Jan 2, 2026
CVE-2026-0567
7.3

This SQL injection vulnerability in code-projects Content Management System 1.0 allows attackers to manipulate database queries through the /pages.php...

Jan 2, 2026
CVE-2026-0568
7.3

This SQL injection vulnerability in code-projects Online Music Site 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter...

Jan 2, 2026
CVE-2025-15434
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against Yonyou KSOA 9.0 through the /kp/PrintZPYG.jsp file by manipulating...

Jan 2, 2026
CVE-2025-15424
7.3

This CVE describes a SQL injection vulnerability in Yonyou KSOA 9.0 through the /worksheet/agent_worksdel.jsp endpoint. Attackers can manipulate the I...

Jan 2, 2026
CVE-2025-15420
7.3

This CVE describes a SQL injection vulnerability in Yonyou KSOA 9.0's /worksheet/agent_work_report.jsp endpoint via the ID parameter. Attackers can re...

Jan 2, 2026
CVE-2025-15421
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /worksheet/agent_worksadd.jsp endpoint of Yon...

Jan 2, 2026
CVE-2025-15408
7.3

This SQL injection vulnerability in Online Guitar Store 1.0 allows attackers to execute arbitrary SQL commands via the dre_title parameter in the admi...

Jan 1, 2026
CVE-2025-15354
7.3

CVE-2025-15354 is a SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows remote attackers to execute arbitrary SQL co...

Dec 30, 2025
CVE-2025-15353
7.3

This SQL injection vulnerability in itsourcecode Society Management System 1.0 allows attackers to manipulate database queries through the Username pa...

Dec 30, 2025
CVE-2025-15263
7.3

BiggiDroid Simple PHP CMS 1.0 contains a SQL injection vulnerability in the admin login page that allows remote attackers to execute arbitrary SQL com...

Dec 30, 2025
CVE-2025-15257
7.3

This CVE describes a command injection vulnerability in the Edimax BR-6208AC router's web configuration interface. Attackers can execute arbitrary com...

Dec 30, 2025
CVE-2025-15256
7.3

This CVE describes a command injection vulnerability in Edimax BR-6208AC routers that allows remote attackers to execute arbitrary commands on affecte...

Dec 30, 2025
CVE-2025-15243
7.3

CVE-2025-15243 is an SQL injection vulnerability in Simple Stock System 1.0's login.php file that allows remote attackers to execute arbitrary SQL com...

Dec 30, 2025
CVE-2025-15208
7.3

CVE-2025-15208 is a SQL injection vulnerability in the Refugee Food Management System 1.0 that allows attackers to manipulate database queries through...

Dec 29, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,168 CVEs classified as CWE-74, with 104 rated critical and 1,275 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free