CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,787 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 10 of 116
- CVE-2025-13271CRITICALCVSS 9.8EG 9.82025-11-17
A vulnerability was determined in Campcodes School Fees Payment Management System 1.0. This impacts an unknown function of the file /ajax.php?action=login. This manipulation of the argument Username causes sql injection. Remote exploitatio…
- CVE-2025-13267CRITICALCVSS 9.8EG 9.82025-11-17
A vulnerability was detected in SourceCodester Dental Clinic Appointment Reservation System 1.0. Impacted is an unknown function of the file /success.php. Performing manipulation of the argument username/password results in sql injection. …
- CVE-2025-13257CRITICALCVSS 9.8EG 9.82025-11-17
A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /admin/user/index.php?view=edit. The manipulation of the argument ID leads to sql injection…
- CVE-2025-13247CRITICALCVSS 9.8EG 9.82025-11-16
A security flaw has been discovered in PHPGurukul Tourism Management System 1.0. The affected element is an unknown function of the file /admin/user-bookings.php. The manipulation of the argument uid results in sql injection. It is possibl…
- CVE-2025-13210CRITICALCVSS 9.8EG 9.82025-11-15
A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=add. Such manipulation of the argument PROMODEL leads to sql injection.…
- CVE-2025-13203CRITICALCVSS 9.8EG 9.82025-11-15
A weakness has been identified in code-projects Simple Cafe Ordering System 1.0. This vulnerability affects unknown code of the file /addmem.php. Executing manipulation of the argument studentnum can lead to sql injection. It is possible t…
- CVE-2025-13201CRITICALCVSS 9.8EG 9.82025-11-15
A vulnerability was identified in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Username leads to sql injection. The attack may…
- CVE-2025-13170CRITICALCVSS 9.8EG 9.82025-11-14
A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/edit_account.php. Performing a manipulation of the argument admin_id results in sql inj…
- CVE-2025-13169CRITICALCVSS 9.8EG 9.82025-11-14
A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /add_query_reserve.php. Such manipulation of the argument room_id leads to sql inje…
- CVE-2025-13122CRITICALCVSS 9.8EG 9.82025-11-13
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppointment of the file /php/api_patient_checkin.php. Performing manipulation of the argument …
- CVE-2025-64741CRITICALCVSS 9.8EG 9.82025-11-13
Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
- CVE-2025-12939CRITICALCVSS 9.8EG 9.82025-11-10
A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of the argument candName results in sql injec…
- CVE-2025-12938CRITICALCVSS 9.8EG 9.82025-11-10
A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknown functionality of the file /process_login.php. The manipulation of the argument keywords leads to sql injection. The a…
- CVE-2025-12933CRITICALCVSS 9.8EG 9.82025-11-10
A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatewelcome.php?id=siteoptions&action=welcome. Such manipulation of the argument roleid leads to sql injection. The attack c…
- CVE-2025-12932CRITICALCVSS 9.8EG 9.82025-11-10
A vulnerability was determined in SourceCodester Baby Care System 1.0. Affected by this issue is some unknown functionality of the file /admin.php?id=inbox. This manipulation of the argument msgid causes sql injection. The attack can be in…
- CVE-2025-12931CRITICALCVSS 9.8EG 9.82025-11-10
A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/edit-orders.php. The manipulation of the argument ID results in sql injection. It is poss…
- CVE-2025-12930CRITICALCVSS 9.8EG 9.82025-11-10
A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /view-ticket.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remo…
- CVE-2025-12929CRITICALCVSS 9.8EG 9.82025-11-10
A flaw has been found in SourceCodester Survey Application System 1.0. This impacts the function save_user/update_user of the file /LoginRegistration.php. Executing manipulation of the argument fullname can lead to sql injection. The attac…
- CVE-2025-12928CRITICALCVSS 9.8EG 9.82025-11-10
A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in sql injection. The attack is possible to…
- CVE-2025-12913CRITICALCVSS 9.8EG 9.82025-11-08
A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomdel.php. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotel…
- CVE-2025-12873CRITICALCVSS 9.8EG 9.82025-11-07
A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /admin/update_user.php. Performing manipulation of the argument user_id results in sql injection. It is possible to initi…
- CVE-2025-12857CRITICALCVSS 9.8EG 9.82025-11-07
A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/roombook.php. Such manipulation of the argument rid leads to sql injection. The attack ca…
- CVE-2025-12856CRITICALCVSS 9.8EG 9.82025-11-07
A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/reservation.php. This manipulation of the argument email causes sql injection. The attack can be initiated remote…
- CVE-2025-12855CRITICALCVSS 9.8EG 9.82025-11-07
A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processing of the file /admin/newsletterdel.php. The manipulation of the argument eid results in sql injection. It is possible …
- CVE-2025-12853CRITICALCVSS 9.8EG 9.82025-11-07
A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function delete_house of the file /admin_class.php. Executing manipulation of the argument ID can lead to sql injection. The attack …
- CVE-2025-12339CRITICALCVSS 9.8EG 9.82025-10-28
A security vulnerability has been detected in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file /admin/admin_football.php. The manipulation of the argument pid leads to sql injection.…
- CVE-2025-12338CRITICALCVSS 9.8EG 9.82025-10-28
A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file /admin/admin_product.ph. Executing a manipulation of the argument pid can lead to sql injection. The a…
- CVE-2025-12337CRITICALCVSS 9.8EG 9.82025-10-28
A security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file /admin/admin_feature.php. Performing a manipulation of the argument pid results in sql injection. The attack…
- CVE-2025-12336CRITICALCVSS 9.8EG 9.82025-10-28
A vulnerability was identified in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_index.php. Such manipulation of the argument Username leads to sql injection…
- CVE-2025-12325CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initia…
- CVE-2025-12316CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability was identified in code-projects Courier Management System 1.0. This impacts an unknown function of the file /courier/edit-courier.php. The manipulation of the argument OfficeName leads to sql injection. The attack is possib…
- CVE-2025-12315CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability was determined in code-projects Food Ordering System 1.0. This affects an unknown function of the file /admin/menu.php. Executing a manipulation of the argument itemPrice can lead to sql injection. The attack can be execute…
- CVE-2025-12314CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability was found in code-projects Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/deleteitem.php. Performing a manipulation of the argument itemID results in sql injection. Remote exploitat…
- CVE-2025-12313CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1. The affected element is an unknown function of the file /msp_info.htm. Such manipulation of the argument cmd leads to command injection. The attack may be launche…
- CVE-2025-12309CRITICALCVSS 9.8EG 9.82025-10-27
A weakness has been identified in code-projects Nero Social Networking Site 1.0. This affects an unknown part of the file /friendprofile.php. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the…
- CVE-2025-12308CRITICALCVSS 9.8EG 9.82025-10-27
A security flaw has been discovered in code-projects Nero Social Networking Site 1.0. Affected by this issue is some unknown functionality of the file /deletemessage.php. Performing manipulation of the argument message_id results in sql in…
- CVE-2025-12307CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability was identified in code-projects Nero Social Networking Site 1.0. Affected by this vulnerability is an unknown functionality of the file /addfriend.php. Such manipulation of the argument ID leads to sql injection. The attack…
- CVE-2025-12306CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability was determined in code-projects Nero Social Networking Site 1.0. Affected is an unknown function of the file /acceptoffres.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried…
- CVE-2025-12294CRITICALCVSS 9.8EG 9.82025-10-27
A security flaw has been discovered in SourceCodester Point of Sales 1.0. Impacted is an unknown function of the file /delete_category.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated re…
- CVE-2025-12293CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability was identified in SourceCodester Point of Sales 1.0. This issue affects some unknown processing of the file /category.php. Such manipulation of the argument Category leads to sql injection. It is possible to launch the atta…
- CVE-2025-12292CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability was determined in SourceCodester Point of Sales 1.0. This vulnerability affects unknown code of the file /index.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack rem…
- CVE-2025-12257CRITICALCVSS 9.8EG 9.82025-10-27
A security vulnerability has been detected in SourceCodester Online Student Result System 1.0. This issue affects some unknown processing of the file /view_result.php. The manipulation of the argument ID leads to sql injection. The attack …
- CVE-2025-12253CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/portal/get_expiredtime.php. This manipulation of the argument uid causes sql injectio…
- CVE-2025-12237CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /index.php. Such manipulation of the argument keywords leads to sql injection. The attack can be executed r…
- CVE-2025-12226CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. Impacted is the function save_house of the file /admin_class.php. Performing manipulation of the argument house_no results in sql injection. Remote exploi…
- CVE-2025-12215CRITICALCVSS 9.8EG 9.82025-10-27
A flaw has been found in projectworlds Online Shopping System 1.0. Impacted is an unknown function of the file /login_submit.php. Executing a manipulation of the argument keywords can lead to sql injection. The attack may be launched remot…
- CVE-2025-12208CRITICALCVSS 9.8EG 9.82025-10-27
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. This impacts the function login2 of the file /admin_class.php. Performing manipulation of the argument Username results in sql injection. The attack is po…
- CVE-2025-11736CRITICALCVSS 9.8EG 9.82025-10-14
A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /index.php. This manipulation of the argument Username causes sql injection. It is possible to initiate t…
- CVE-2025-11664CRITICALCVSS 9.8EG 9.82025-10-13
A security vulnerability has been detected in Campcodes Online Beauty Parlor Management System 1.0. The impacted element is an unknown function of the file /admin/search-appointment.php. Such manipulation of the argument searchdata leads t…
- CVE-2025-11662CRITICALCVSS 9.8EG 9.82025-10-13
A security flaw has been discovered in SourceCodester Best Salon Management System 1.0. Impacted is an unknown function of the file /booking.php. The manipulation of the argument serv_id results in sql injection. It is possible to launch t…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →