CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,170
Total CVEs
104
Critical
1,277
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
221
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,170)

CVE-2025-14653
7.3

CVE-2025-14653 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows attackers to manipulate database queries th...

Dec 14, 2025
CVE-2025-14652
7.3

CVE-2025-14652 is an SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows attackers to manipulate database queries ...

Dec 14, 2025
CVE-2025-14650
7.3

CVE-2025-14650 is a SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows remote attackers to execute arbitrary SQL ...

Dec 14, 2025
CVE-2025-14649
7.3

CVE-2025-14649 is an SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows remote attackers to execute arbitrary SQL...

Dec 14, 2025
CVE-2025-14647
7.3

CVE-2025-14647 is a SQL injection vulnerability in Computer Book Store 1.0 that allows remote attackers to execute arbitrary SQL commands via the 'boo...

Dec 14, 2025
CVE-2025-14645
7.3

This SQL injection vulnerability in code-projects Student File Management System 1.0 allows attackers to execute arbitrary SQL commands via the user_i...

Dec 14, 2025
CVE-2025-14646
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'stud_id' parameter in the /admin/delete_student.php file in code...

Dec 14, 2025
CVE-2025-14644
7.3

CVE-2025-14644 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...

Dec 14, 2025
CVE-2025-14643
7.3

This SQL injection vulnerability in Simple Attendance Record System 2.0 allows attackers to manipulate database queries through the student parameter ...

Dec 14, 2025
CVE-2025-14640
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against the Student File Management System 1.0 by manipulating the stud_no...

Dec 14, 2025
CVE-2025-14639
7.3

CVE-2025-14639 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL co...

Dec 14, 2025
CVE-2025-14638
7.3

This SQL injection vulnerability in itsourcecode Online Pet Shop Management System 1.0 allows attackers to manipulate database queries through the /pe...

Dec 14, 2025
CVE-2025-14637
7.3

This SQL injection vulnerability in itsourcecode Online Pet Shop Management System 1.0 allows remote attackers to execute arbitrary SQL commands via t...

Dec 13, 2025
CVE-2025-14622
7.3

This SQL injection vulnerability in code-projects Student File Management System 1.0 allows attackers to execute arbitrary SQL commands through the fi...

Dec 13, 2025
CVE-2025-14623
7.3

This SQL injection vulnerability in code-projects Student File Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

Dec 13, 2025
CVE-2025-14621
7.3

This SQL injection vulnerability in code-projects Student File Management System 1.0 allows attackers to manipulate database queries through the user_...

Dec 13, 2025
CVE-2025-14619
7.3

This vulnerability allows remote attackers to execute SQL injection attacks via the 'stud_no' parameter in the login_query.php file of Student File Ma...

Dec 13, 2025
CVE-2025-14620
7.3

CVE-2025-14620 is an SQL injection vulnerability in code-projects Student File Management System 1.0 that allows attackers to manipulate database quer...

Dec 13, 2025
CVE-2025-14588
7.3

CVE-2025-14588 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL co...

Dec 13, 2025
CVE-2025-14590
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'keyname' parameter in the /admin/search1.php file of Prison Mana...

Dec 13, 2025
CVE-2025-14587
7.3

This SQL injection vulnerability in itsourcecode Online Pet Shop Management System 1.0 allows remote attackers to execute arbitrary SQL commands via t...

Dec 13, 2025
CVE-2025-14585
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /admin/?page=zone endpoint of itsourcecode CO...

Dec 12, 2025
CVE-2025-14584
7.3

This SQL injection vulnerability in the itsourcecode COVID Tracking System 1.0 allows attackers to manipulate database queries through the admin login...

Dec 12, 2025
CVE-2025-14578
7.3

CVE-2025-14578 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...

Dec 12, 2025
CVE-2025-14571
7.3

This CVE describes an SQL injection vulnerability in the Advanced Library Management System 1.0 by projectworlds. Attackers can exploit the roll_numbe...

Dec 12, 2025
CVE-2025-14570
7.3

CVE-2025-14570 is a SQL injection vulnerability in Advanced Library Management System 1.0 that allows attackers to execute arbitrary SQL commands via ...

Dec 12, 2025
CVE-2025-14565
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands through the Username parameter in the /Profilers/SProfile/login1.php file...

Dec 12, 2025
CVE-2025-14566
7.3

This CVE describes a SQL injection vulnerability in kidaze CourseSelectionSystem that allows remote attackers to execute arbitrary SQL commands via th...

Dec 12, 2025
CVE-2025-14537
7.3

CVE-2025-14537 is a SQL injection vulnerability in code-projects Class and Exam Timetable Management 1.0 that allows attackers to manipulate database ...

Dec 11, 2025
CVE-2025-14536
7.3

CVE-2025-14536 is an SQL injection vulnerability in code-projects Class and Exam Timetable Management 1.0 that allows attackers to execute arbitrary S...

Dec 11, 2025
CVE-2025-14515
7.3

Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/add_unit.php file via the txtunitDetails parameter. This...

Dec 11, 2025
CVE-2025-14514
7.3

Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/add_distributor.php file via the txtDistributorAddress p...

Dec 11, 2025
CVE-2025-14337
7.3

CVE-2025-14337 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL co...

Dec 9, 2025
CVE-2025-14335
7.3

CVE-2025-14335 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...

Dec 9, 2025
CVE-2025-14336
7.3

This vulnerability allows remote attackers to execute SQL injection attacks against the itsourcecode Student Management System 1.0 via the 'sy' parame...

Dec 9, 2025
CVE-2025-14334
7.3

CVE-2025-14334 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows attackers to execute arbitrary SQL commands ...

Dec 9, 2025
CVE-2025-14285
7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'per_id' parameter in the edit_personnel.php file of Employee Pro...

Dec 9, 2025
CVE-2025-14258
7.3

CVE-2025-14258 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...

Dec 8, 2025
CVE-2025-14256
7.3

CVE-2025-14256 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...

Dec 8, 2025
CVE-2025-14257
7.3

CVE-2025-14257 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL co...

Dec 8, 2025
CVE-2025-14250
7.3

CVE-2025-14250 is a SQL injection vulnerability in code-projects Online Ordering System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Dec 8, 2025
CVE-2025-14251
7.3

CVE-2025-14251 is an SQL injection vulnerability in code-projects Online Ordering System 1.0 that allows attackers to manipulate database queries thro...

Dec 8, 2025
CVE-2025-14248
7.3

CVE-2025-14248 is an SQL injection vulnerability in Simple Shopping Cart 1.0's admin login page that allows attackers to execute arbitrary SQL command...

Dec 8, 2025
CVE-2025-14249
7.3

CVE-2025-14249 is a SQL injection vulnerability in code-projects Online Ordering System 1.0 that allows attackers to manipulate database queries throu...

Dec 8, 2025
CVE-2025-14245
7.3

This SQL injection vulnerability in IdeaCMS allows remote attackers to execute arbitrary SQL commands through the whereRaw function in Coupon.php. It ...

Dec 8, 2025
CVE-2025-14226
7.3

This SQL injection vulnerability in itsourcecode Student Management System 1.0 allows attackers to manipulate database queries through the fname param...

Dec 8, 2025
CVE-2025-14223
7.3

CVE-2025-14223 is an SQL injection vulnerability in Simple Leave Manager 1.0 that allows attackers to manipulate database queries through the staff_id...

Dec 8, 2025
CVE-2025-14218
7.3

CVE-2025-14218 is a SQL injection vulnerability in code-projects Currency Exchange System 1.0 that allows remote attackers to execute arbitrary SQL co...

Dec 8, 2025
CVE-2025-14216
7.3

CVE-2025-14216 is a SQL injection vulnerability in code-projects Currency Exchange System 1.0 that allows remote attackers to execute arbitrary SQL co...

Dec 8, 2025
CVE-2025-14217
7.3

CVE-2025-14217 is a SQL injection vulnerability in code-projects Currency Exchange System 1.0 that allows remote attackers to execute arbitrary SQL co...

Dec 8, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,170 CVEs classified as CWE-74, with 104 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free