CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,785 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 5 of 116
- CVE-2026-2529CRITICALCVSS 9.8EG 9.82026-02-16
A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list results in command injection. The at…
- CVE-2026-2528CRITICALCVSS 9.8EG 9.82026-02-16
A vulnerability was identified in Wavlink WL-WN579A3 up to 20210219. Affected by this vulnerability is the function Delete_Mac_list of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list leads to command injection.…
- CVE-2026-2527CRITICALCVSS 9.8EG 9.82026-02-16
A vulnerability was determined in Wavlink WL-WN579A3 up to 20210219. Affected is an unknown function of the file /cgi-bin/login.cgi. Executing a manipulation of the argument key can lead to command injection. The attack may be launched rem…
- CVE-2026-25814CRITICALCVSS 9.8EG 9.82026-02-09
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, User-controlled query parameters are passed directly into DynamoDB query/filter construction without validation or sanitization.
- CVE-2026-2225CRITICALCVSS 9.8EG 9.82026-02-09
A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argument email causes sql injection. The att…
- CVE-2026-2223CRITICALCVSS 9.8EG 9.82026-02-09
A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the file /system/system/students/assessments/pretest/take/index.php. The manipulation of the ar…
- CVE-2026-2221CRITICALCVSS 9.8EG 9.82026-02-09
A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the file /login/index.php of the component Login. Performing a manipulation of the argument Username results in sql injecti…
- CVE-2026-2220CRITICALCVSS 9.8EG 9.82026-02-09
A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file /system/system/admins/assessments/pretest/btn_functions.php. Such manipulation of the argument difficulty_id leads to …
- CVE-2026-2217CRITICALCVSS 9.8EG 9.82026-02-09
A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/manage_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched…
- CVE-2026-2212CRITICALCVSS 9.8EG 9.82026-02-09
A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /Administrator/PHP/AdminEditCategory.php. The manipulation of the argument ID leads to sql inject…
- CVE-2026-2211CRITICALCVSS 9.8EG 9.82026-02-09
A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Administrator/PHP/AdminDeleteCategory.php. Executing a manipulation of the argument ID can lead to sql injection. The attac…
- CVE-2026-2199CRITICALCVSS 9.8EG 9.82026-02-09
A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. Performing a manipulation of the argument…
- CVE-2026-2198CRITICALCVSS 9.8EG 9.82026-02-09
A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficulty_id lea…
- CVE-2026-2197CRITICALCVSS 9.8EG 9.82026-02-09
A vulnerability was determined in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/admins/assessments/pretest/exam-delete.php. This manipulation of the argument test_id causes sql injecti…
- CVE-2026-2196CRITICALCVSS 9.8EG 9.82026-02-09
A vulnerability was found in code-projects Online Reviewer System 1.0. This issue affects some unknown processing of the file /system/system/admins/assessments/pretest/exam-update.php. The manipulation of the argument test_id results in sq…
- CVE-2026-2195CRITICALCVSS 9.8EG 9.82026-02-09
A vulnerability has been found in code-projects Online Reviewer System 1.0. This vulnerability affects unknown code of the file /system/system/admins/assessments/pretest/questions-view.php. The manipulation of the argument ID leads to sql …
- CVE-2026-2190CRITICALCVSS 9.8EG 9.82026-02-08
A security flaw has been discovered in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/user/controller.php. The manipulation of the argument ID results in sql injection. The attack can be l…
- CVE-2026-2189CRITICALCVSS 9.8EG 9.82026-02-08
A vulnerability was identified in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/report/index.php. The manipulation of the argument ay leads to sql injection. The attack can be initiated r…
- CVE-2026-2173CRITICALCVSS 9.8EG 9.82026-02-08
A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attac…
- CVE-2026-2172CRITICALCVSS 9.8EG 9.82026-02-08
A vulnerability was determined in code-projects Online Application System for Admission 1.0. Affected by this vulnerability is an unknown functionality of the file enrollment/index.php of the component Login Endpoint. Executing a manipulat…
- CVE-2026-2171CRITICALCVSS 9.8EG 9.82026-02-08
A vulnerability was found in code-projects Online Student Management System 1.0. Affected is an unknown function of the file accounts.php of the component Login. Performing a manipulation of the argument username/password results in sql in…
- CVE-2026-2166CRITICALCVSS 9.8EG 9.82026-02-08
A security vulnerability has been detected in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /login/index.php of the component Login. The manipulation of the argument username/password lea…
- CVE-2026-2161CRITICALCVSS 9.8EG 9.82026-02-08
A vulnerability was found in itsourcecode Directory Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/forget-password.php. The manipulation of the argument email results in sql injection. The at…
- CVE-2026-2158CRITICALCVSS 9.8EG 9.82026-02-08
A vulnerability was detected in code-projects Student Web Portal 1.0. This impacts an unknown function of the file /check_user.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the…
- CVE-2026-2136CRITICALCVSS 9.8EG 9.82026-02-08
A flaw has been found in projectworlds Online Food Ordering System 1.0. This affects an unknown function of the file /view-ticket.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the atta…
- CVE-2026-2132CRITICALCVSS 9.8EG 9.82026-02-08
A security flaw has been discovered in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Administrator/PHP/AdminUpdateCategory.php. The manipulation of the argument txtcat results in sql injection…
- CVE-2026-2130CRITICALCVSS 9.8EG 9.82026-02-08
A vulnerability was determined in BurtTheCoder mcp-maigret up to 1.0.12. This affects an unknown part of the file src/index.ts of the component search_username. Executing a manipulation of the argument Username can lead to command injectio…
- CVE-2026-2122CRITICALCVSS 9.8EG 9.82026-02-08
A security flaw has been discovered in Xiaopi Panel up to 20260126. This impacts an unknown function of the file /demo.php of the component WAF Firewall. The manipulation of the argument ID results in sql injection. The attack may be launc…
- CVE-2026-2117CRITICALCVSS 9.8EG 9.82026-02-08
A vulnerability was found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/edit_activity.php. Performing a manipulation of the argument activity_id results in sql injection. The …
- CVE-2026-2116CRITICALCVSS 9.8EG 9.82026-02-08
A vulnerability has been found in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/edit_expenses.php. Such manipulation of the argument expenses_id leads to sql injection. It is possible to lau…
- CVE-2026-2115CRITICALCVSS 9.8EG 9.82026-02-07
A flaw has been found in itsourcecode Society Management System 1.0. This issue affects some unknown processing of the file /admin/delete_expenses.php. This manipulation of the argument expenses_id causes sql injection. It is possible to i…
- CVE-2026-2114CRITICALCVSS 9.8EG 9.82026-02-07
A vulnerability was detected in itsourcecode Society Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_admin.php. The manipulation of the argument admin_id results in sql injection. The attack may be pe…
- CVE-2026-2090CRITICALCVSS 9.8EG 9.82026-02-07
A vulnerability was determined in SourceCodester Online Class Record System 1.0. This issue affects some unknown processing of the file /admin/message/search.php. Executing a manipulation of the argument term can lead to sql injection. The…
- CVE-2026-2089CRITICALCVSS 9.8EG 9.82026-02-07
A vulnerability was found in SourceCodester Online Class Record System 1.0. This vulnerability affects unknown code of the file /admin/subject/controller.php. Performing a manipulation of the argument ID results in sql injection. Remote ex…
- CVE-2026-2088CRITICALCVSS 9.8EG 9.82026-02-07
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid leads to sql injection. The attack may be …
- CVE-2026-2087CRITICALCVSS 9.8EG 9.82026-02-07
A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. This manipulation of the argument user_email causes sql injection. The attack may be…
- CVE-2026-2083CRITICALCVSS 9.8EG 9.82026-02-07
A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file /delete_post.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initia…
- CVE-2026-2073CRITICALCVSS 9.8EG 9.82026-02-07
A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/user/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be pe…
- CVE-2026-2060CRITICALCVSS 9.8EG 9.82026-02-06
A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /simpleblooddonor/editcampaignform.php. Performing a manipulation of the argument I…
- CVE-2026-2059CRITICALCVSS 9.8EG 9.82026-02-06
A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown function of the file /emp_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack may be perfor…
- CVE-2026-2058CRITICALCVSS 9.8EG 9.82026-02-06
A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquerypublic.php of the component Post Query Details Page. This manipulation …
- CVE-2026-2057CRITICALCVSS 9.8EG 9.82026-02-06
A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown function of the file /login.php. The manipulation of the argument User results in sql injection. The attack can be executed…
- CVE-2026-2018CRITICALCVSS 9.8EG 9.82026-02-06
A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/settings/controller.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attac…
- CVE-2026-2014CRITICALCVSS 9.8EG 9.82026-02-06
A security flaw has been discovered in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /ramonsys/billing/index.php. Performing a manipulation of the argument ID results in sql injection. Remote expl…
- CVE-2026-2013CRITICALCVSS 9.8EG 9.82026-02-06
A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched rem…
- CVE-2026-2012CRITICALCVSS 9.8EG 9.82026-02-06
A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /ramonsys/facultyloading/index.php. This manipulation of the argument ID causes sql injection. The attack…
- CVE-2026-2011CRITICALCVSS 9.8EG 9.82026-02-06
A vulnerability was found in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /ramonsys/enrollment/controller.php. The manipulation of the argument ID results in sql injection. The attack …
- CVE-2026-1701CRITICALCVSS 9.8EG 9.82026-01-30
A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown processing of the file /enrollment/index.php. Such manipulation of the argument ID leads to sql injection. It is possi…
- CVE-2026-1688CRITICALCVSS 9.8EG 9.82026-01-30
A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. The att…
- CVE-2026-1595CRITICALCVSS 9.8EG 9.82026-01-29
A vulnerability was detected in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_student_query.php. The manipulation of the argument student_id results in sql injection. The attack can be exe…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →