CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,787 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 7 of 116
- CVE-2026-0590CRITICALCVSS 9.8EG 9.82026-01-05
A vulnerability was determined in code-projects Online Product Reservation System 1.0. The affected element is an unknown function of the file /app/checkout/delete.php of the component POST Parameter Handler. This manipulation of the argum…
- CVE-2026-0585CRITICALCVSS 9.8EG 9.82026-01-05
A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the file /order_view.php of the component GET Parameter Handler. Such manipulation of the argument transa…
- CVE-2026-0584CRITICALCVSS 9.8EG 9.82026-01-05
A weakness has been identified in code-projects Online Product Reservation System 1.0. This issue affects some unknown processing of the file app/products/left_cart.php. This manipulation of the argument ID causes sql injection. Remote exp…
- CVE-2026-0583CRITICALCVSS 9.8EG 9.82026-01-05
A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This vulnerability affects unknown code of the file app/user/login.php of the component User Login. The manipulation of the argument emailadd resul…
- CVE-2026-0582CRITICALCVSS 9.8EG 9.82026-01-05
A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_activity_query.php. The manipulation of the argument Title leads to sql injection. The attack may be initiat…
- CVE-2026-0581CRITICALCVSS 9.8EG 9.82026-01-05
A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/d…
- CVE-2026-0579CRITICALCVSS 9.8EG 9.82026-01-04
A vulnerability was found in code-projects Online Product Reservation System 1.0. This affects an unknown part of the file /handgunner-administrator/edit.php of the component POST Parameter Handler. The manipulation of the argument prod_id…
- CVE-2026-0578CRITICALCVSS 9.8EG 9.82026-01-04
A vulnerability has been found in code-projects Online Product Reservation System 1.0. Affected by this issue is some unknown functionality of the file /handgunner-administrator/delete.php. The manipulation of the argument ID leads to sql …
- CVE-2026-0576CRITICALCVSS 9.8EG 9.82026-01-04
A vulnerability was detected in code-projects Online Product Reservation System 1.0. Affected is an unknown function of the file /handgunner-administrator/prod.php of the component Parameter Handler. Performing a manipulation of the argume…
- CVE-2026-0575CRITICALCVSS 9.8EG 9.82026-01-04
A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. This impacts an unknown function of the file /handgunner-administrator/adminlogin.php of the component Administrator Login. Such manipulatio…
- CVE-2026-0570CRITICALCVSS 9.8EG 9.82026-01-02
A vulnerability was found in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Frontend/Feedback.php. Performing a manipulation of the argument fname results in sql injection. The attack can be initiated re…
- CVE-2026-0569CRITICALCVSS 9.8EG 9.82026-01-02
A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown function of the file /Frontend/AlbumByCategory.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the at…
- CVE-2026-0568CRITICALCVSS 9.8EG 9.82026-01-02
A flaw has been found in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Frontend/ViewSongs.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack…
- CVE-2026-0567CRITICALCVSS 9.8EG 9.82026-01-02
A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function of the file /pages.php. The manipulation of the argument ID results in sql injection. The attack may be performed from…
- CVE-2026-0565CRITICALCVSS 9.8EG 9.82026-01-02
A weakness has been identified in code-projects Content Management System 1.0. This issue affects some unknown processing of the file /admin/delete.php. Executing a manipulation of the argument del can lead to sql injection. The attack can…
- CVE-2026-0546CRITICALCVSS 9.8EG 9.82026-01-02
A vulnerability was determined in code-projects Content Management System 1.0. This impacts an unknown function of the file search.php. This manipulation of the argument Value causes sql injection. The attack is possible to be carried out …
- CVE-2025-15436CRITICALCVSS 9.8EG 9.82026-01-02
A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such manipulation of the argument Report leads to sql injection. The attack can be launched remot…
- CVE-2025-15435CRITICALCVSS 9.8EG 9.82026-01-02
A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_update.jsp. This manipulation of the argument Report causes sql injection. The attack can be initiated remotel…
- CVE-2025-15434CRITICALCVSS 9.8EG 9.82026-01-02
A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The manipulation of the argument zpjhid results in sql injection. It is possible to launch the attack remotely. The exploit is …
- CVE-2025-15425CRITICALCVSS 9.8EG 9.82026-01-02
A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_user.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql inj…
- CVE-2025-15424CRITICALCVSS 9.8EG 9.82026-01-02
A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /worksheet/agent_worksdel.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument ID results in sql in…
- CVE-2025-15421CRITICALCVSS 9.8EG 9.82026-01-02
A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection. T…
- CVE-2025-15420CRITICALCVSS 9.8EG 9.82026-01-02
A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent_work_report.jsp. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The…
- CVE-2025-15410CRITICALCVSS 9.8EG 9.82026-01-01
A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument L_email leads to sql injection. It is possible to initia…
- CVE-2025-15409CRITICALCVSS 9.8EG 9.82026-01-01
A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Delete_product.php. Executing a manipulation of the argument del_pro can lead to sql inj…
- CVE-2025-15408CRITICALCVSS 9.8EG 9.82026-01-01
A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/Create_product.php. Performing a manipulation of the argument dre_title results in sql injection. The attack is possible…
- CVE-2025-15407CRITICALCVSS 9.8EG 9.82026-01-01
A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /admin/Create_category.php. Such manipulation of the argument dre_Ctitle leads to sql injection. The attack can be execut…
- CVE-2026-0544CRITICALCVSS 9.8EG 9.82026-01-01
A security flaw has been discovered in itsourcecode School Management System 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attac…
- CVE-2025-15391CRITICALCVSS 9.8EG 9.82025-12-31
A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP Request Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been…
- CVE-2025-15243CRITICALCVSS 9.8EG 9.82025-12-30
A flaw has been found in code-projects Simple Stock System 1.0. This affects an unknown function of the file /market/login.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotel…
- CVE-2025-15212CRITICALCVSS 9.8EG 9.82025-12-30
A vulnerability was detected in code-projects Refugee Food Management System 1.0. This issue affects some unknown processing of the file /home/regfood.php. Performing manipulation of the argument a results in sql injection. Remote exploita…
- CVE-2025-15211CRITICALCVSS 9.8EG 9.82025-12-30
A flaw has been found in code-projects Refugee Food Management System 1.0. Impacted is an unknown function of the file /home/refugee.php. Executing manipulation of the argument refNo/Fname/Lname/sex/age/contact/nationality_nid can lead to …
- CVE-2025-15210CRITICALCVSS 9.8EG 9.82025-12-30
A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This vulnerability affects unknown code of the file /home/editrefugee.php. Such manipulation of the argument a/b/c/sex/d/e/nationality_nid lead…
- CVE-2025-15209CRITICALCVSS 9.8EG 9.82025-12-29
A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown part of the file /home/editfood.php. This manipulation of the argument a/b/c/d causes sql injection. The attack may be initiated re…
- CVE-2025-15208CRITICALCVSS 9.8EG 9.82025-12-29
A security flaw has been discovered in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file /home/editrefugee.php. The manipulation of the argument rfid results in sql injection…
- CVE-2025-15207CRITICALCVSS 9.8EG 9.82025-12-29
A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/view_products.php. The manipulation of the argument chkId[] leads to sql injection. It is possible to initiate t…
- CVE-2025-15206CRITICALCVSS 9.8EG 9.82025-12-29
A flaw has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /admin/add_area.php. Executing a manipulation of the argument txtAreaCode can lead to sql injection. The attack may be performe…
- CVE-2025-15198CRITICALCVSS 9.8EG 9.82025-12-29
A weakness has been identified in code-projects College Notes Uploading System 1.0. This issue affects some unknown processing of the file /login.php. Executing a manipulation of the argument User can lead to sql injection. The attack may …
- CVE-2025-15196CRITICALCVSS 9.8EG 9.82025-12-29
A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file login.php. Such manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploi…
- CVE-2025-15195CRITICALCVSS 9.8EG 9.82025-12-29
A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file /admin/add-module.php. This manipulation of the argument linked[] causes sql injection. The attack …
- CVE-2025-15186CRITICALCVSS 9.8EG 9.82025-12-29
A vulnerability has been found in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file /home/addusers.php. Such manipulation of the argument a leads to sql injection. It is poss…
- CVE-2025-15185CRITICALCVSS 9.8EG 9.82025-12-29
A flaw has been found in code-projects Refugee Food Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /home/refugeesreport.php. This manipulation of the argument a causes sql injection. It is pos…
- CVE-2025-15184CRITICALCVSS 9.8EG 9.82025-12-29
A vulnerability was detected in code-projects Refugee Food Management System 1.0. Affected is an unknown function of the file /home/refugeesreport2.php. The manipulation of the argument a results in sql injection. The attack may be perform…
- CVE-2025-15183CRITICALCVSS 9.8EG 9.82025-12-29
A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This impacts an unknown function of the file /home/viewtakenfd.php. The manipulation of the argument tfid leads to sql injection. The attack is…
- CVE-2025-15182CRITICALCVSS 9.8EG 9.82025-12-29
A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown function of the file /home/served.php. Executing manipulation of the argument refNo can lead to sql injection. The attack can be ex…
- CVE-2025-15181CRITICALCVSS 9.8EG 9.82025-12-29
A security flaw has been discovered in code-projects Refugee Food Management System 1.0. The impacted element is an unknown function of the file /home/pagenateRefugeesList.php. Performing manipulation of the argument rfid results in sql in…
- CVE-2025-15168CRITICALCVSS 9.8EG 9.82025-12-29
A vulnerability was identified in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /statistical.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. T…
- CVE-2025-15167CRITICALCVSS 9.8EG 9.82025-12-29
A vulnerability was determined in itsourcecode Online Cake Ordering System 1.0. This impacts an unknown function of the file /detailtransac.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack i…
- CVE-2025-15166CRITICALCVSS 9.8EG 9.82025-12-29
A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown function of the file /updatesupplier.php?action=edit. The manipulation of the argument ID results in sql injection. The attack may be launch…
- CVE-2025-15165CRITICALCVSS 9.8EG 9.82025-12-29
A vulnerability has been found in itsourcecode Online Cake Ordering System 1.0. The impacted element is an unknown function of the file /updatecustomer.php?action=edit. The manipulation of the argument ID leads to sql injection. The attack…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →