CWE-99— Improper Control of Resource Identifiers (Resource Injection)
The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.— MITRE CWE catalog
72 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-99page 2 of 2
- CVE-2026-10624MEDIUMCVSS 4.3EG 4.32026-06-02
A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the file /detailview.php of the component Employee View Page. Such manipulation of the argument e…
- CVE-2026-5031MEDIUMCVSS 4.3EG 4.32026-03-29
A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_route=settings/users-view/ of the component Endpoint. The manipulation of the argument ID results in improper control o…
- CVE-2025-12270MEDIUMCVSS 4.3EG 4.32025-10-27
A vulnerability was determined in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The impacted element is an unknown function of the file /api/v1/assignments/{assignment_id}/tasks/{task_id}/sub_file of the component Student Assi…
- CVE-2025-9263MEDIUMCVSS 4.3EG 4.32025-08-20
A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument j…
- CVE-2025-8793MEDIUMCVSS 4.3EG 4.32025-08-10
A vulnerability classified as problematic was found in LitmusChaos Litmus up to 3.19.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument projectID leads to improper control of resource identifier…
- CVE-2025-3855MEDIUMCVSS 4.3EG 4.32025-04-22
A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php/team_members/save_profile_image/ of the component Profil…
- CVE-2025-3405MEDIUMCVSS 4.3EG 4.32025-04-08
A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /rest/cliente/ObterPedido/ of the component HTTP GET Reques…
- CVE-2025-2125MEDIUMCVSS 4.3EG 4.32025-03-09
A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. This vulnerability affects unknown code of the file /v2/report.svc/comprovante_marcacao/?companyId=1 of the component PDF Document Handler. The man…
- CVE-2025-1642MEDIUMCVSS 4.3EG 4.32025-02-25
A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been declared as critical. This vulnerability affects unknown code of the file /AGE0000700/GetImageMedico?fooId=1. The manipulation of the argument fooId leads to improper …
- CVE-2025-1575MEDIUMCVSS 4.3EG 4.32025-02-23
A vulnerability classified as problematic has been found in Harpia DiagSystem 12. Affected is an unknown function of the file /diagsystem/PACS/atualatendimento_jpeg.php. The manipulation of the argument cod/codexame leads to improper contr…
- CVE-2024-6051MEDIUMCVSS 4.3EG 4.32024-09-30
Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection and to manipulate the view of a vulnerable application.This issue affects Redlink SDK versions through 1.13.
- CVE-2024-7438MEDIUMCVSS 4.3EG 4.32024-08-03
A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Al…
- CVE-2023-2200MEDIUMCVSS 4.1EG 4.12023-07-13
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML i…
- CVE-2026-10299LOWCVSS 3.8EG 3.82026-06-01
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resourc…
- CVE-2026-7303LOWCVSS 3.7EG 3.72026-04-28
A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Execution Log Handler…
- CVE-2025-12919LOWCVSS 3.7EG 3.72025-11-09
A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in impr…
- CVE-2026-107448LOWCVSS 3.4EG 3.42026-10-08
Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directly to the Windows shell via Application.O…
- CVE-2026-13493LOWCVSS 3.1EG 3.12026-06-28
A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the component Workflow Checkpoint Restore Handler. Executing a manipulation can…
- CVE-2025-12918LOWCVSS 3.1EG 3.12025-11-09
A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an unknown function of the file /dashboard/fees/fee-invoices/ of the component View Fee Invoice. Performing manipulation of…
- CVE-2025-0625LOWCVSS 3.1EG 3.12025-01-22
A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. This affects an unknown part of the component Attachment Handler. The manipulation leads to improper control of resource identifie…
- CVE-2024-0231LOWCVSS 2.7EG 2.72024-07-24
A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.
- CVE-2026-106583LOWCVSS 2.5EG 2.52026-10-06
In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection.
Map vulnerabilities like CWE-99 to your infrastructure
EchelonGraph correlates every CVE — across CWE-99 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →