CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,170
Total CVEs
104
Critical
1,277
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
221
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,170)

CVE-2025-15243
7.3

CVE-2025-15243 is an SQL injection vulnerability in Simple Stock System 1.0's login.php file that allows remote attackers to execute arbitrary SQL com...

Dec 30, 2025
CVE-2025-15208
7.3

CVE-2025-15208 is a SQL injection vulnerability in the Refugee Food Management System 1.0 that allows attackers to manipulate database queries through...

Dec 29, 2025
CVE-2025-15206
7.3

Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/add_area.php file via the txtAreaCode parameter. This al...

Dec 29, 2025
CVE-2025-15207
7.3

Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/view_products.php file through manipulation of the chkId...

Dec 29, 2025
CVE-2025-15198
7.3

CVE-2025-15198 is a SQL injection vulnerability in the College Notes Uploading System 1.0 that allows attackers to manipulate database queries through...

Dec 29, 2025
CVE-2025-15196
7.3

CVE-2025-15196 is an SQL injection vulnerability in code-projects Assessment Management 1.0 that allows attackers to execute arbitrary SQL commands vi...

Dec 29, 2025
CVE-2025-15195
7.3

CVE-2025-15195 is a SQL injection vulnerability in code-projects Assessment Management 1.0 that allows remote attackers to execute arbitrary SQL comma...

Dec 29, 2025
CVE-2025-15186
7.3

This SQL injection vulnerability in Refugee Food Management System 1.0 allows attackers to manipulate database queries through the 'a' parameter in /h...

Dec 29, 2025
CVE-2025-15185
7.3

CVE-2025-15185 is a SQL injection vulnerability in the Refugee Food Management System 1.0 that allows remote attackers to execute arbitrary SQL comman...

Dec 29, 2025
CVE-2025-15184
7.3

This SQL injection vulnerability in Refugee Food Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'a' parameter in /ho...

Dec 29, 2025
CVE-2025-15183
7.3

This SQL injection vulnerability in Refugee Food Management System 1.0 allows attackers to manipulate database queries through the tfid parameter in /...

Dec 29, 2025
CVE-2025-15182
7.3

CVE-2025-15182 is a SQL injection vulnerability in code-projects Refugee Food Management System 1.0 that allows remote attackers to execute arbitrary ...

Dec 29, 2025
CVE-2025-15181
7.3

CVE-2025-15181 is an SQL injection vulnerability in the Refugee Food Management System 1.0 that allows attackers to manipulate database queries throug...

Dec 29, 2025
CVE-2025-15168
7.3

CVE-2025-15168 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...

Dec 29, 2025
CVE-2025-15167
7.3

CVE-2025-15167 is a SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows attackers to execute arbitrary SQL command...

Dec 29, 2025
CVE-2025-15166
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /updatesupplier.php?action=edit endpoint of i...

Dec 29, 2025
CVE-2025-15165
7.3

CVE-2025-15165 is an SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows remote attackers to execute arbitrary SQL...

Dec 29, 2025
CVE-2025-15142
7.3

This CVE describes a SQL injection vulnerability in phpok3w's show.php file through manipulation of the ID parameter. Attackers can remotely exploit t...

Dec 28, 2025
CVE-2025-15140
7.3

This SQL injection vulnerability in the saiftheboss7 onlinemcqexam software allows attackers to manipulate database queries through the ans1/ans2 para...

Dec 28, 2025
CVE-2025-15127
7.3

This CVE describes an SQL injection vulnerability in FantasticLBP Hotels_Server's Room.php API endpoint. Attackers can exploit the hotelId parameter t...

Dec 28, 2025
CVE-2025-15078
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against itsourcecode Student Management System 1.0 through the /list_repor...

Dec 25, 2025
CVE-2025-15077
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against itsourcecode Student Management System 1.0 via the ID parameter in...

Dec 25, 2025
CVE-2025-15075
7.3

CVE-2025-15075 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL co...

Dec 25, 2025
CVE-2025-15074
7.3

CVE-2025-15074 is a SQL injection vulnerability in itsourcecode Online Frozen Foods Ordering System 1.0 that allows remote attackers to execute arbitr...

Dec 25, 2025
CVE-2025-15073
7.3

CVE-2025-15073 is an SQL injection vulnerability in itsourcecode Online Frozen Foods Ordering System 1.0 that allows remote attackers to execute arbit...

Dec 24, 2025
CVE-2025-15053
7.3

This SQL injection vulnerability in code-projects Student Information System 1.0 allows attackers to manipulate database queries through the searchbox...

Dec 24, 2025
CVE-2025-15048
7.3

This vulnerability allows remote attackers to execute arbitrary commands on Tenda WH450 routers by injecting malicious input into the 'ipaddress' para...

Dec 23, 2025
CVE-2025-15049
7.3

CVE-2025-15049 is a SQL injection vulnerability in code-projects Online Farm System 1.0 that allows attackers to execute arbitrary SQL commands via th...

Dec 23, 2025
CVE-2025-15034
7.3

CVE-2025-15034 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...

Dec 23, 2025
CVE-2025-15012
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'a' parameter in /home/home.php in code-projects Refugee Food Man...

Dec 22, 2025
CVE-2025-15011
7.3

This SQL injection vulnerability in Simple Stock System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'uname' parameter in /lo...

Dec 22, 2025
CVE-2025-15002
7.3

This SQL injection vulnerability in SeaCMS allows remote attackers to execute arbitrary SQL commands through manipulated page/limit parameters in the ...

Dec 21, 2025
CVE-2025-14990
7.3

This CVE describes a SQL injection vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0. Attackers can remotely exploit the ...

Dec 21, 2025
CVE-2025-14989
7.3

This SQL injection vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0 allows attackers to execute arbitrary SQL commands t...

Dec 21, 2025
CVE-2025-14968
7.3

CVE-2025-14968 is an SQL injection vulnerability in Simple Stock System 1.0 that allows remote attackers to execute arbitrary SQL commands via the ema...

Dec 19, 2025
CVE-2025-14959
7.3

CVE-2025-14959 is an SQL injection vulnerability in Simple Stock System 1.0 that allows remote attackers to execute arbitrary SQL commands through the...

Dec 19, 2025
CVE-2025-14951
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against the Scholars Tracking System 1.0 by manipulating the post_content ...

Dec 19, 2025
CVE-2025-14952
7.3

Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/add_category.php file via the txtCategoryName parameter....

Dec 19, 2025
CVE-2025-14950
7.3

CVE-2025-14950 is an SQL injection vulnerability in code-projects Scholars Tracking System 1.0 that allows attackers to execute arbitrary SQL commands...

Dec 19, 2025
CVE-2025-14940
7.3

This SQL injection vulnerability in Scholars Tracking System 1.0 allows attackers to execute arbitrary SQL commands via the ID parameter in /admin/del...

Dec 19, 2025
CVE-2025-14877
7.3

This SQL injection vulnerability in Campcodes Supplier Management System 1.0 allows attackers to execute arbitrary SQL commands through the cmbAreaCod...

Dec 18, 2025
CVE-2025-14833
7.3

This CVE describes a SQL injection vulnerability in code-projects Online Appointment Booking System 1.0. Attackers can remotely exploit the /admin/del...

Dec 17, 2025
CVE-2025-14832
7.3

CVE-2025-14832 is an SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows remote attackers to execute arbitrary SQL...

Dec 17, 2025
CVE-2025-14710
7.3

This SQL injection vulnerability in FantasticLBP Hotels Server allows attackers to execute arbitrary SQL commands by manipulating the 'telephone' para...

Dec 15, 2025
CVE-2025-14711
7.3

This SQL injection vulnerability in FantasticLBP Hotels Server allows remote attackers to execute arbitrary SQL commands via the pickedHotelName/type ...

Dec 15, 2025
CVE-2025-14668
7.3

This SQL injection vulnerability in campcodes Advanced Online Examination System 1.0 allows attackers to manipulate database queries through the Usern...

Dec 14, 2025
CVE-2025-14666
7.3

CVE-2025-14666 is an SQL injection vulnerability in itsourcecode COVID Tracking System 1.0 that allows remote attackers to execute arbitrary SQL comma...

Dec 14, 2025
CVE-2025-14667
7.3

CVE-2025-14667 is a SQL injection vulnerability in itsourcecode COVID Tracking System 1.0 that allows remote attackers to execute arbitrary SQL comman...

Dec 14, 2025
CVE-2025-14664
7.3

Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/view_unit.php file through manipulation of the chkId[] p...

Dec 14, 2025
CVE-2025-14661
7.3

This SQL injection vulnerability in itsourcecode Student Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'sy' ...

Dec 14, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,170 CVEs classified as CWE-74, with 104 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free