CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,217 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 40 of 105
- CVE-2025-1157MEDIUMCVSS 6.3EG 6.32025-02-10
A vulnerability was found in Allims lab.online up to 20250201 and classified as critical. This issue affects some unknown processing of the file /model/model_recuperar_senha.php. The manipulation of the argument recuperacao leads to sql in…
- CVE-2025-1158MEDIUMCVSS 6.3EG 6.32025-02-10
A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unknown function of the file addPolicyToSafetyGroup.jsp. The manipulation of the argument safetyGroupId leads to sql injec…
- CVE-2025-11582HIGHCVSS 7.3EG 7.32025-10-10
A vulnerability was detected in code-projects Online Job Search Engine 1.0. This issue affects some unknown processing of the file /registration.php. Performing manipulation of the argument txtusername results in sql injection. The attack …
- CVE-2025-11583HIGHCVSS 7.3EG 7.32025-10-10
A flaw has been found in code-projects Online Job Search Engine 1.0. Impacted is an unknown function of the file /postjob.php. Executing manipulation of the argument txtjobID can lead to sql injection. The attack may be launched remotely. …
- CVE-2025-11584HIGHCVSS 7.3EG 7.32025-10-10
A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown function of the file /searchjob.php. The manipulation of the argument txtspecialization leads to sql injection. Remote exploit…
- CVE-2025-11585HIGHCVSS 7.3EG 7.32025-10-10
A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /useredit.php. The manipulation of the argument uid results in sql injection. The attack can be executed remo…
- CVE-2025-11588MEDIUMCVSS 6.3EG 6.32025-10-10
A vulnerability was identified in CodeAstro Gym Management System 1.0. This impacts an unknown function of the file /customer/index.php. Such manipulation of the argument fullname leads to sql injection. The attack may be performed from re…
- CVE-2025-11589MEDIUMCVSS 6.3EG 6.32025-10-10
A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/user-payment.php. Performing a manipulation of the argument plan results in sql injection. It is possible to ini…
- CVE-2025-11590MEDIUMCVSS 6.3EG 6.32025-10-11
A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing a manipulation of the argument ename can lead to sql inject…
- CVE-2025-11591MEDIUMCVSS 6.3EG 6.32025-10-11
A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/actions/delete-member.php. The manipulation of the argument ID leads to sql injectio…
- CVE-2025-11592MEDIUMCVSS 6.3EG 6.32025-10-11
A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edit-equipmentform.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely.…
- CVE-2025-11593MEDIUMCVSS 6.3EG 6.32025-10-11
A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin/actions/delete-equipment.php. This manipulation of the argument ID causes sql injection. The attack may be initiated r…
- CVE-2025-11595MEDIUMCVSS 4.7EG 4.72025-10-11
A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /admin-profile.php. Performing a manipulation of the argument mobilenumber results in sql injection. Remote …
- CVE-2025-11596HIGHCVSS 7.3EG 7.32025-10-11
A vulnerability was determined in code-projects E-Commerce Website 1.0. The affected element is an unknown function of the file /pages/delete_order_details.php. Executing manipulation of the argument order_id can lead to sql injection. The…
- CVE-2025-11597MEDIUMCVSS 6.3EG 6.32025-10-11
A vulnerability was identified in code-projects E-Commerce Website 1.0. The impacted element is an unknown function of the file /pages/product_add_qty.php. The manipulation of the argument prod_id leads to sql injection. The attack is poss…
- CVE-2025-11599HIGHCVSS 7.3EG 7.32025-10-11
A weakness has been identified in Campcodes Online Apartment Visitor Management System 1.0. This impacts an unknown function of the file /forgot-password.php. This manipulation of the argument email causes sql injection. It is possible to …
- CVE-2025-11600MEDIUMCVSS 6.3EG 6.32025-10-11
A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file editcategory.php. Such manipulation of the argument cname leads to sql injection. It is possible to la…
- CVE-2025-11601HIGHCVSS 7.3EG 7.32025-10-11
A vulnerability was detected in SourceCodester Online Student Result System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing manipulation of the argument Username results in sql injection. …
- CVE-2025-11603MEDIUMCVSS 6.3EG 6.32025-10-11
A vulnerability was found in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /editproduct.php. The manipulation of the argument Category results in sql injection. The attack may be launche…
- CVE-2025-11604HIGHCVSS 7.3EG 7.32025-10-11
A vulnerability was determined in projectworlds Online Ordering Food System 1.0. This issue affects some unknown processing of the file /all-orders.php. This manipulation of the argument Status causes sql injection. Remote exploitation of …
- CVE-2025-11605MEDIUMCVSS 6.3EG 6.32025-10-11
A vulnerability was identified in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/update-profile.php. Such manipulation of the argument uid leads to sql injection. The attack can be executed remo…
- CVE-2025-11606MEDIUMCVSS 6.3EG 6.32025-10-11
A security flaw has been discovered in iPynch Social Network Website up to b6933b6d7f82c84819abe458ccf0e59d61119541. The affected element is an unknown function of the component Search. Performing manipulation results in sql injection. The…
- CVE-2025-11608HIGHCVSS 7.3EG 7.32025-10-11
A security vulnerability has been detected in code-projects E-Banking System 1.0. This affects an unknown function of the file /register.php of the component POST Parameter Handler. The manipulation of the argument username/password leads …
- CVE-2025-11610MEDIUMCVSS 6.3EG 6.32025-10-11
A security flaw has been discovered in SourceCodester Simple Inventory System 1.0. This issue affects some unknown processing of the file /brand.php. The manipulation of the argument editBrandName results in sql injection. The attack can b…
- CVE-2025-11611MEDIUMCVSS 6.3EG 6.32025-10-11
A weakness has been identified in SourceCodester Simple Inventory System 1.0. Impacted is an unknown function of the file /user.php. This manipulation of the argument uemail causes sql injection. The attack is possible to be carried out re…
- CVE-2025-11612MEDIUMCVSS 6.3EG 6.32025-10-11
A vulnerability has been found in code-projects Simple Food Ordering System 1.0. This impacts an unknown function of the file /addproduct.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated re…
- CVE-2025-11613MEDIUMCVSS 6.3EG 6.32025-10-11
A vulnerability was found in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file /addcategory.php. The manipulation of the argument cname results in sql injection. The attack can be launched remotely.…
- CVE-2025-11614HIGHCVSS 7.3EG 7.32025-10-11
A vulnerability was identified in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown functionality of the file /panel/edit-appointment.php. Such manipulation of the argument editid leads to sql injectio…
- CVE-2025-11615HIGHCVSS 7.3EG 7.32025-10-11
A security flaw has been discovered in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/add_invoice.php. Performing manipulation of the argument ServiceId results in sql injection. Remote exp…
- CVE-2025-1162MEDIUMCVSS 6.3EG 6.32025-02-10
A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /\_parse/load\_user-profile.php. The manipulation of the argument userhash leads to sql injection. It is p…
- CVE-2025-11628MEDIUMCVSS 4.7EG 4.72025-10-12
A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This affects an unknown function of the file /delete.php of the component Product Inventory Handler. This manipulation of the…
- CVE-2025-11629MEDIUMCVSS 6.3EG 6.32025-10-12
A vulnerability has been found in RainyGao DocSys up to 2.02.36. This impacts the function getUserList of the file /Manage/getUserList.do. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit …
- CVE-2025-11654HIGHCVSS 7.3EG 7.32025-10-13
A vulnerability was identified in yousaf530 Inferno Online Clothing Store up to 827dd42bfbe380e8de76fdc67958c24cf1246208. The affected element is an unknown function of the file /log.php. Such manipulation of the argument cemail/password l…
- CVE-2025-11662HIGHCVSS 7.3EG 7.32025-10-13
A security flaw has been discovered in SourceCodester Best Salon Management System 1.0. Impacted is an unknown function of the file /booking.php. The manipulation of the argument serv_id results in sql injection. It is possible to launch t…
- CVE-2025-11663MEDIUMCVSS 4.7EG 4.72025-10-13
A weakness has been identified in Campcodes Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/manage-services.php. This manipulation of the argument sername causes sql injection. The…
- CVE-2025-11664MEDIUMCVSS 4.7EG 4.72025-10-13
A security vulnerability has been detected in Campcodes Online Beauty Parlor Management System 1.0. The impacted element is an unknown function of the file /admin/search-appointment.php. Such manipulation of the argument searchdata leads t…
- CVE-2025-11667MEDIUMCVSS 6.3EG 6.32025-10-13
A vulnerability was found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_candidate_modal.php.. The manipulation of the argument firstname results in sql injec…
- CVE-2025-11668MEDIUMCVSS 4.7EG 4.72025-10-13
A vulnerability was determined in code-projects Automated Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/update_user.php. This manipulation of the argument Password causes sql injection. The atta…
- CVE-2025-1167MEDIUMCVSS 6.3EG 6.32025-02-11
A vulnerability was found in Mayuri K Employee Management System up to 192.168.70.3 and classified as critical. Affected by this issue is some unknown functionality of the file /hr_soft/admin/Update_User.php. The manipulation of the argume…
- CVE-2025-1168MEDIUMCVSS 6.3EG 6.32025-02-11
A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-contact.php. The manipulation of the argument contac…
- CVE-2025-1172MEDIUMCVSS 6.3EG 6.32025-02-11
A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affected by this issue is some unknown functionality of the file addtocart.php. The manipulation of the argument bcid leads…
- CVE-2025-1173MEDIUMCVSS 4.7EG 4.72025-02-11
A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affects an unknown part of the file process_users_del.php. The manipulation of the argument id leads to sql injection. It i…
- CVE-2025-11736HIGHCVSS 7.3EG 7.32025-10-14
A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /index.php. This manipulation of the argument Username causes sql injection. It is possible to initiate t…
- CVE-2025-1183MEDIUMCVSS 6.3EG 6.32025-02-12
A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/admin/more-userprofile.php. The manipulation of the argument…
- CVE-2025-1184MEDIUMCVSS 6.3EG 6.32025-02-12
A vulnerability was found in pihome-shc PiHome 1.77 and classified as critical. Affected by this issue is some unknown functionality of the file /ajax.php?Ajax=GetModal_MQTTEdit. The manipulation of the argument id leads to sql injection. …
- CVE-2025-1185MEDIUMCVSS 6.3EG 6.32025-02-12
A vulnerability was found in pihome-shc PiHome 2.0. It has been classified as critical. This affects an unknown part of the file /ajax.php?Ajax=GetModal_Sensor_Graph. The manipulation leads to sql injection. It is possible to initiate the …
- CVE-2025-1188MEDIUMCVSS 6.3EG 6.32025-02-12
A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/updateroutine.php. The manipulation of the argument …
- CVE-2025-1189MEDIUMCVSS 6.3EG 6.32025-02-12
A vulnerability, which was classified as critical, was found in 1000 Projects Attendance Tracking Management System 1.0. This affects an unknown part of the file /admin/chart1.php. The manipulation of the argument course_id leads to sql in…
- CVE-2025-11902MEDIUMCVSS 6.3EG 6.32025-10-17
A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findField of the file /cms/article/findField. Performing a manipulation of the argument cid results in sql injection. The atta…
- CVE-2025-11903MEDIUMCVSS 6.3EG 6.32025-10-17
A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cms/article/update. Executing a manipulation of the argument cid can lead to sql injection. The attack can be launched re…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →