CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,785 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 4 of 116
- CVE-2026-3765CRITICALCVSS 9.8EG 9.82026-03-08
A vulnerability was identified in itsourcecode University Management System 1.0. This affects an unknown function of the file /att_single_view.php. Such manipulation of the argument dt leads to sql injection. The attack can be launched rem…
- CVE-2026-3760CRITICALCVSS 9.8EG 9.82026-03-08
A vulnerability was detected in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /view_result.php. Performing a manipulation of the argument seme results in sql injection. The attack is pos…
- CVE-2026-3759CRITICALCVSS 9.8EG 9.82026-03-08
A security vulnerability has been detected in projectworlds Online Art Gallery Shop 1.0. This affects an unknown part of the file /admin/adminHome.php. Such manipulation of the argument reach_nm leads to sql injection. The attack can be ex…
- CVE-2026-3758CRITICALCVSS 9.8EG 9.82026-03-08
A weakness has been identified in projectworlds Online Art Gallery Shop 1.0. Affected by this issue is some unknown functionality of the file /admin/adminHome.php. This manipulation of the argument Info causes sql injection. Remote exploit…
- CVE-2026-3757CRITICALCVSS 9.8EG 9.82026-03-08
A security flaw has been discovered in projectworlds Online Art Gallery Shop 1.0. Affected by this vulnerability is an unknown functionality of the file /?pass=1. The manipulation of the argument fnm results in sql injection. The attack ma…
- CVE-2026-3747CRITICALCVSS 9.8EG 9.82026-03-08
A vulnerability was identified in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /add_result.php. Such manipulation of the argument subject leads to sql injection. The attack…
- CVE-2026-3746CRITICALCVSS 9.8EG 9.82026-03-08
A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of the component Login. This manipulation of …
- CVE-2026-3744CRITICALCVSS 9.8EG 9.82026-03-08
A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql injection. The attack can be initiated re…
- CVE-2026-3740CRITICALCVSS 9.8EG 9.82026-03-08
A weakness has been identified in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_search_student.php. This manipulation of the argument admin_search_student causes sql injection. The attack…
- CVE-2026-3736CRITICALCVSS 9.8EG 9.82026-03-08
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulation of the argument from results in sql i…
- CVE-2026-3735CRITICALCVSS 9.8EG 9.82026-03-08
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulation of the argument from leads to sql inj…
- CVE-2026-3730CRITICALCVSS 9.8EG 9.82026-03-08
A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/mod_amenities/index.php?view=edit. Performing a manipulation of the argument amen_i…
- CVE-2026-3723CRITICALCVSS 9.8EG 9.82026-03-08
A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /Admindelete.php. The manipulation of the argument flightno results in sql injection. The attack may…
- CVE-2026-3709CRITICALCVSS 9.8EG 9.82026-03-08
A weakness has been identified in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /register.php. Executing a manipulation of the argument Username can lead to sql injection. The attack ma…
- CVE-2026-3708CRITICALCVSS 9.8EG 9.82026-03-08
A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. The impacted element is an unknown function of the file /login.php. Performing a manipulation of the argument Username results in sql injection. …
- CVE-2026-3705CRITICALCVSS 9.8EG 9.82026-03-08
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. This issue affects some unknown processing of the file /Adminsearch.php. The manipulation of the argument flightno results in sql injection. It is possible…
- CVE-2026-29186CRITICALCVSS 9.8EG 9.82026-03-07
Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to fi…
- CVE-2026-29053CRITICALCVSS 9.8EG 9.82026-03-05
Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.
- CVE-2026-26002CRITICALCVSS 9.8EG 9.82026-03-04
Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory. This has been patched in versions 4.0.…
- CVE-2026-3413CRITICALCVSS 9.8EG 9.82026-03-02
A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php. This manipulation of the argument ID causes sql injection. The attack is possible to be …
- CVE-2026-3411CRITICALCVSS 9.8EG 9.82026-03-02
A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /admin_single_student_update.php. The manipulation of the argument ID leads to sq…
- CVE-2026-3410CRITICALCVSS 9.8EG 9.82026-03-02
A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/check_studid.php. Executing a manipulation of the argument student_id can lead to s…
- CVE-2026-3406CRITICALCVSS 9.8EG 9.82026-03-02
A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the component Registration Handler. The manipulation of the argument fname results i…
- CVE-2026-3395CRITICALCVSS 9.8EG 9.82026-03-01
A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can l…
- CVE-2026-3287CRITICALCVSS 9.8EG 9.82026-02-27
A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/main/java/com/youlai/mall/pms/controller/app/SpuController.java of the component App-side P…
- CVE-2026-3261CRITICALCVSS 9.8EG 9.82026-02-26
A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipulation of the argument ID causes sql injection. The attack ma…
- CVE-2026-27727CRITICALCVSS 9.8EG 9.82026-02-25
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked w…
- CVE-2026-3164CRITICALCVSS 9.8EG 9.82026-02-25
A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The manipulation of the argument pagetitle results in sql injection. It is possible to launch t…
- CVE-2026-3153CRITICALCVSS 9.8EG 9.82026-02-25
A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attac…
- CVE-2026-3152CRITICALCVSS 9.8EG 9.82026-02-25
A flaw has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/teacher-salary.php. This manipulation of the argument teacher_id causes sql injection. It is possible to ini…
- CVE-2026-3151CRITICALCVSS 9.8EG 9.82026-02-25
A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /login/login.php. The manipulation of the argument email results in sql injection. The attack may be performed …
- CVE-2026-3148CRITICALCVSS 9.8EG 9.82026-02-25
A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username causes sql injection. The attack may be initiat…
- CVE-2026-3135CRITICALCVSS 9.8EG 9.82026-02-25
A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.php. This manipulation of the argument Category causes sql injection. It is possible to ini…
- CVE-2026-3134CRITICALCVSS 9.8EG 9.82026-02-25
A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admin/edit-category.php. The manipulation of the argument Category results in sql injection. T…
- CVE-2026-3133CRITICALCVSS 9.8EG 9.82026-02-25
A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processing of the file /loging.php of the component Login. The manipulation of the argument Username leads to sql injection. Rem…
- CVE-2026-3069CRITICALCVSS 9.8EG 9.82026-02-24
A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown function of the file /edtlbls.php. The manipulation of the argument field1 leads to sql injection. The attack may be initiate…
- CVE-2026-3068CRITICALCVSS 9.8EG 9.82026-02-24
A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to sql injection. The attack can be launch…
- CVE-2026-3057CRITICALCVSS 9.8EG 9.82026-02-24
A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Interface. The manipulation of the argument p…
- CVE-2026-3046CRITICALCVSS 9.8EG 9.82026-02-24
A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The manipulation of the argument profile_id le…
- CVE-2026-3042CRITICALCVSS 9.8EG 9.82026-02-24
A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. Performing a manipulation of the argument ID results in sql injection. The attack is possib…
- CVE-2026-2954CRITICALCVSS 9.8EG 9.82026-02-22
A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a manipulation of the argument driverClassNa…
- CVE-2026-2912CRITICALCVSS 9.8EG 9.82026-02-22
A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessments/results/studentresult-view.php. The manipulation of the argument test_id results in sql …
- CVE-2026-2867CRITICALCVSS 9.8EG 9.82026-02-21
A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched re…
- CVE-2026-2865CRITICALCVSS 9.8EG 9.82026-02-21
A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroller.php of the component HTTP POST Request Handler. Performing a manipulation of the argume…
- CVE-2026-27194CRITICALCVSS 9.8EG 9.82026-02-21
D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing…
- CVE-2026-2848CRITICALCVSS 9.8EG 9.82026-02-20
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component Registration. This manipulation of the ar…
- CVE-2026-2691CRITICALCVSS 9.8EG 9.82026-02-19
A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/manage_register.php. Such manipulation of the argument ID leads to sql injection. It is pos…
- CVE-2026-2690CRITICALCVSS 9.8EG 9.82026-02-19
A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. This manipulation of the argument Username…
- CVE-2026-2689CRITICALCVSS 9.8EG 9.82026-02-19
A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The manipulation of the argument ID results in sql injection. The attack may be performed from…
- CVE-2026-2682CRITICALCVSS 9.8EG 9.82026-02-18
A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /mine/PublicReport/prinReport.html?token=java. Such manipulation of the argument comid lead…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →