CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,788 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 19 of 116
- CVE-2025-8185CRITICALCVSS 9.8EG 9.82025-07-26
A vulnerability was found in 1000 Projects ABC Courier Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /getbyid.php. The manipulation of the argument ID leads to sql injection. It is p…
- CVE-2025-8179CRITICALCVSS 9.8EG 9.82025-07-26
A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/changeimage.php. The manipulation of the argum…
- CVE-2025-8173CRITICALCVSS 9.8EG 9.82025-07-25
A vulnerability has been found in 1000 Projects ABC Courier Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /Add_reciver.php. The manipulation of the argument reciver…
- CVE-2025-8166CRITICALCVSS 9.8EG 9.82025-07-25
A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/index.php of the component HTTP POST Request Handler. The manipulation of the arg…
- CVE-2025-8125CRITICALCVSS 9.8EG 9.82025-07-25
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/role/authUser/allocatedList. The manipulation of the argument params[dataSco…
- CVE-2025-7950CRITICALCVSS 9.8EG 9.82025-07-22
A vulnerability was found in code-projects Public Chat Room 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. …
- CVE-2025-7933CRITICALCVSS 9.8EG 9.82025-07-21
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/settings_update.php of the component Setting Handler. The manipulation of the argument…
- CVE-2025-7930CRITICALCVSS 9.8EG 9.82025-07-21
A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /members/add_members.php. The manipulation of the argument mobi…
- CVE-2025-7929CRITICALCVSS 9.8EG 9.82025-07-21
A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is an unknown function of the file /members/edit_Members.php. The manipulation of the argument fname leads to sql injection…
- CVE-2025-7928CRITICALCVSS 9.8EG 9.82025-07-21
A vulnerability was found in code-projects Church Donation System 1.0 and classified as critical. This issue affects some unknown processing of the file /members/edit_user.php. The manipulation of the argument firstname leads to sql inject…
- CVE-2025-7915CRITICALCVSS 9.8EG 9.82025-07-21
A vulnerability was found in Chanjet CRM 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /mail/mailinactive.php of the component Login Page. The manipulation leads to sql injection. The atta…
- CVE-2025-7894CRITICALCVSS 9.8EG 9.82025-07-20
A vulnerability, which was classified as critical, has been found in Onyx up to 0.29.1. This issue affects the function generate_simple_sql of the file backend/onyx/agents/agent_search/kb_search/nodes/a3_generate_simple_sql.py of the compo…
- CVE-2025-7888CRITICALCVSS 9.8EG 9.82025-07-20
A vulnerability was found in TDuckCloud tduck-platform 5.1 and classified as critical. This issue affects the function UserFormDataMapper of the file src/main/java/com/tduck/cloud/form/mapper/UserFormDataMapper.java. The manipulation of th…
- CVE-2025-7873CRITICALCVSS 9.8EG 9.82025-07-20
A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file mcc_login.jsp. The manipulation of the argument workerid leads…
- CVE-2025-7861CRITICALCVSS 9.8EG 9.82025-07-20
A vulnerability, which was classified as critical, was found in code-projects Church Donation System 1.0. Affected is an unknown function of the file /members/search.php. The manipulation of the argument Username leads to sql injection. It…
- CVE-2025-7860CRITICALCVSS 9.8EG 9.82025-07-20
A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file /members/login_admin.php. The manipulation of the argument Username leads…
- CVE-2025-7859CRITICALCVSS 9.8EG 9.82025-07-20
A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects unknown code of the file /members/update_password_admin.php. The manipulation of the argument new_password leads to sq…
- CVE-2025-7838CRITICALCVSS 9.8EG 9.82025-07-19
A vulnerability has been found in Campcodes Online Movie Theater Seat Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage_seat.php. The manipulation of the argument ID leads …
- CVE-2025-7833CRITICALCVSS 9.8EG 9.82025-07-19
A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file /members/giving.php. The manipulation of the argument Amount leads to sql…
- CVE-2025-7832CRITICALCVSS 9.8EG 9.82025-07-19
A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects unknown code of the file /members/offering.php. The manipulation of the argument trcode leads to sql injection. The at…
- CVE-2025-7831CRITICALCVSS 9.8EG 9.82025-07-19
A vulnerability classified as critical has been found in code-projects Church Donation System 1.0. This affects an unknown part of the file /members/Tithes.php. The manipulation of the argument trcode leads to sql injection. It is possible…
- CVE-2025-7830CRITICALCVSS 9.8EG 9.82025-07-19
A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /reg.php. The manipulation of the argument mobile leads to sql injection…
- CVE-2025-7829CRITICALCVSS 9.8EG 9.82025-07-19
A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument Username leads to …
- CVE-2025-7814CRITICALCVSS 9.8EG 9.82025-07-18
A vulnerability classified as critical was found in code-projects Food Ordering Review System 1.0. This vulnerability affects unknown code of the file /pages/signup_function.php. The manipulation of the argument fname leads to sql injectio…
- CVE-2025-7765CRITICALCVSS 9.8EG 9.82025-07-17
A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/addmanagerclinic.php. The manipulation of the argument c…
- CVE-2025-7764CRITICALCVSS 9.8EG 9.82025-07-17
A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /admin/deletedoctorclinic.php. The manipulation of the argument clinic leads to sql i…
- CVE-2025-7757CRITICALCVSS 9.8EG 9.82025-07-17
A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit-property.php. The manipulation of the argument editid leads to sql injectio…
- CVE-2025-7753CRITICALCVSS 9.8EG 9.82025-07-17
A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/adddoctor.php. The manipulation of the argument Username leads to sql inj…
- CVE-2025-7752CRITICALCVSS 9.8EG 9.82025-07-17
A vulnerability was found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/deletedoctor.php. The manipulation of the argument did lea…
- CVE-2025-7751CRITICALCVSS 9.8EG 9.82025-07-17
A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/addclinic.php. The manipulation of the argument…
- CVE-2025-7750CRITICALCVSS 9.8EG 9.82025-07-17
A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /admin/adddoctorclinic.php. The manipulation of the argument clinic leads to s…
- CVE-2025-7749CRITICALCVSS 9.8EG 9.82025-07-17
A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the file /admin/getmanagerregion.php. The manipulation of the argument …
- CVE-2025-7612CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability was found in code-projects Mobile Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument email leads to sql injection. The attack can be …
- CVE-2025-7611CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability was found in code-projects Wedding Reservation 1.0. It has been classified as critical. This affects an unknown part of the file /global.php. The manipulation of the argument lu leads to sql injection. It is possible to ini…
- CVE-2025-7610CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability was found in code-projects Electricity Billing System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user/change_password.php. The manipulation of the argument new_password…
- CVE-2025-7609CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument ruser_email leads t…
- CVE-2025-7608CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an unknown function of the file /userlogin.php. The manipulation of the argument user_email leads to sql injection. It is p…
- CVE-2025-7607CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability, which was classified as critical, has been found in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Customers/save_order.php. The manipulation of the argument order_price lea…
- CVE-2025-7606CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability classified as critical has been found in code-projects AVL Rooms 1.0. This affects an unknown part of the file /city.php. The manipulation of the argument city leads to sql injection. It is possible to initiate the attack r…
- CVE-2025-7605CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability was found in code-projects AVL Rooms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument first_name leads to sql injection. The…
- CVE-2025-7604CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user-login.php. The manipulation of the argument Username lea…
- CVE-2025-7595CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability was found in code-projects Job Diary 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /view-cad.php. The manipulation of the argument ID leads to sql injection. The attack can be in…
- CVE-2025-7594CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability was found in code-projects Job Diary 1.0. It has been classified as critical. This affects an unknown part of the file /view-emp.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate th…
- CVE-2025-7593CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability was found in code-projects Job Diary 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view-all.php. The manipulation of the argument ID leads to sql injection. The attack may…
- CVE-2025-7587CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /cover.php. The manipulation of the argument uname/psw leads …
- CVE-2025-7542CRITICALCVSS 9.8EG 9.82025-07-13
A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/user-profile.php. The manipulation of the …
- CVE-2025-7541CRITICALCVSS 9.8EG 9.82025-07-13
A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /get_town.php. The manipulation of the argument countr…
- CVE-2025-7540CRITICALCVSS 9.8EG 9.82025-07-13
A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /getclinic.php. The manipulation of the argument townid leads to sql injection…
- CVE-2025-7539CRITICALCVSS 9.8EG 9.82025-07-13
A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the file /getdoctordaybooking.php. The manipulation of the argument cid…
- CVE-2025-7537CRITICALCVSS 9.8EG 9.82025-07-13
A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /pages/product_update.php. The manipulation of the argument ID leads to sql injection. It is possib…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →