CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,217 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 42 of 105
- CVE-2025-12316HIGHCVSS 7.3EG 7.32025-10-27
A vulnerability was identified in code-projects Courier Management System 1.0. This impacts an unknown function of the file /courier/edit-courier.php. The manipulation of the argument OfficeName leads to sql injection. The attack is possib…
- CVE-2025-12325HIGHCVSS 7.3EG 7.32025-10-27
A vulnerability has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initia…
- CVE-2025-12326HIGHCVSS 7.3EG 7.32025-10-27
A vulnerability was found in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. This vulnerability affects unknown code of the file /process.php of the component POST Request Handler. The manipulation of the argument un resu…
- CVE-2025-12327MEDIUMCVSS 6.3EG 6.32025-10-27
A vulnerability was determined in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. This issue affects some unknown processing of the file /description.php. This manipulation of the argument ID causes sql injection. The att…
- CVE-2025-12328MEDIUMCVSS 6.3EG 6.32025-10-27
A vulnerability was identified in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. Impacted is an unknown function of the file /contestproblem.php. Such manipulation of the argument Name leads to sql injection. The attack …
- CVE-2025-12329MEDIUMCVSS 6.3EG 6.32025-10-27
A security flaw has been discovered in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. The affected element is an unknown function of the file /details.php. Performing manipulation of the argument ID results in sql inject…
- CVE-2025-12336HIGHCVSS 7.3EG 7.32025-10-28
A vulnerability was identified in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_index.php. Such manipulation of the argument Username leads to sql injection…
- CVE-2025-12337HIGHCVSS 7.3EG 7.32025-10-28
A security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file /admin/admin_feature.php. Performing a manipulation of the argument pid results in sql injection. The attack…
- CVE-2025-12338HIGHCVSS 7.3EG 7.32025-10-28
A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file /admin/admin_product.ph. Executing a manipulation of the argument pid can lead to sql injection. The a…
- CVE-2025-12339HIGHCVSS 7.3EG 7.32025-10-28
A security vulnerability has been detected in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file /admin/admin_football.php. The manipulation of the argument pid leads to sql injection.…
- CVE-2025-12342HIGHCVSS 7.3EG 7.32025-10-28
A flaw has been found in Serdar Bayram Ghost Hot Spot up to 20251014. The affected element is an unknown function of the file /Auth.php of the component Login. This manipulation causes sql injection. The attack is possible to be carried ou…
- CVE-2025-12594MEDIUMCVSS 4.7EG 4.72025-11-02
A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown function of the file /admin/add_account.php. The manipulation of the argument Name results in sql injection. The attac…
- CVE-2025-12597MEDIUMCVSS 4.7EG 4.72025-11-02
A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability is the function save_category of the file /admin_class.php. Performing manipulation of the argument Name results in sql …
- CVE-2025-12598MEDIUMCVSS 4.7EG 4.72025-11-02
A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function save_tenant of the file /admin_class.php. Executing manipulation of the argument firstname can lead to sql injection. T…
- CVE-2025-12604HIGHCVSS 7.3EG 7.32025-11-02
A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_id leads to sql injection. The attack may be initiated remot…
- CVE-2025-12605HIGHCVSS 7.3EG 7.32025-11-02
A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument ID results in sql injection. The attack may be launched rem…
- CVE-2025-12606HIGHCVSS 7.3EG 7.32025-11-03
A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of the argument ID causes sql injection. Remote exploitation o…
- CVE-2025-12607HIGHCVSS 7.3EG 7.32025-11-03
A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remo…
- CVE-2025-12608HIGHCVSS 7.3EG 7.32025-11-03
A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing manipulation of the argument ID results in sql injection. The attac…
- CVE-2025-12609MEDIUMCVSS 4.7EG 4.72025-11-03
A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/update-progress.php. Performing a manipulation of the argument id/ini_weight results in sql injection…
- CVE-2025-12610MEDIUMCVSS 4.7EG 4.72025-11-03
A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/view-progress-report.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launc…
- CVE-2025-12612MEDIUMCVSS 6.3EG 6.32025-11-03
A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_course. The manipulation of the argument ID results in sql injection…
- CVE-2025-12614MEDIUMCVSS 4.7EG 4.72025-11-03
A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of the argument ID causes sql injection. The attack is possib…
- CVE-2025-12617HIGHCVSS 7.3EG 7.32025-11-03
A flaw has been found in itsourcecode Billing System 1.0. This affects an unknown function of the file /admin/app/login_crud.php. Executing a manipulation of the argument Password can lead to sql injection. It is possible to launch the att…
- CVE-2025-12853MEDIUMCVSS 4.7EG 4.72025-11-07
A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function delete_house of the file /admin_class.php. Executing manipulation of the argument ID can lead to sql injection. The attack …
- CVE-2025-12855MEDIUMCVSS 4.7EG 4.72025-11-07
A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processing of the file /admin/newsletterdel.php. The manipulation of the argument eid results in sql injection. It is possible …
- CVE-2025-12856MEDIUMCVSS 4.7EG 4.72025-11-07
A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/reservation.php. This manipulation of the argument email causes sql injection. The attack can be initiated remote…
- CVE-2025-12857MEDIUMCVSS 4.7EG 4.72025-11-07
A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/roombook.php. Such manipulation of the argument rid leads to sql injection. The attack ca…
- CVE-2025-12859MEDIUMCVSS 4.7EG 4.72025-11-07
A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_edit.php. The manipulation of the argument ids leads to sql injection. Remote exploitation of the attack is possible. T…
- CVE-2025-12860MEDIUMCVSS 4.7EG 4.72025-11-07
A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. The manipulation of the argument orderby results in sql injection. The attack can be executed remotely. The exploit has…
- CVE-2025-12861MEDIUMCVSS 4.7EG 4.72025-11-07
A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the file /admin/spec_add.php. This manipulation of the argument flags[] causes sql injection. The attack is possible to be…
- CVE-2025-12873MEDIUMCVSS 4.7EG 4.72025-11-07
A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /admin/update_user.php. Performing manipulation of the argument user_id results in sql injection. It is possible to initi…
- CVE-2025-12913MEDIUMCVSS 4.7EG 4.72025-11-08
A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomdel.php. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotel…
- CVE-2025-12914MEDIUMCVSS 4.7EG 4.72025-11-08
A vulnerability has been found in aaPanel BaoTa up to 11.2.x. This vulnerability affects unknown code of the file /database?action=GetDatabaseAccess of the component Backend. The manipulation of the argument Name leads to sql injection. Th…
- CVE-2025-12916MEDIUMCVSS 6.3EG 6.32025-11-09
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component Frontend. This manipulation of the argument loginUrl causes…
- CVE-2025-12921MEDIUMCVSS 4.3EG 4.32025-11-10
A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by this issue is some unknown functionality of the file /ImportCRFData?action=confirm of the component CRF Data Import. Such manipulation of the ar…
- CVE-2025-12926MEDIUMCVSS 6.3EG 6.32025-11-10
A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function of the file /review.php. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack…
- CVE-2025-12927MEDIUMCVSS 4.7EG 4.72025-11-10
A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the file /admin/archives_add.php. Such manipulation of the argument flags[] leads to sql injection. The attack can be execute…
- CVE-2025-12928HIGHCVSS 7.3EG 7.32025-11-10
A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in sql injection. The attack is possible to…
- CVE-2025-12929HIGHCVSS 7.3EG 7.32025-11-10
A flaw has been found in SourceCodester Survey Application System 1.0. This impacts the function save_user/update_user of the file /LoginRegistration.php. Executing manipulation of the argument fullname can lead to sql injection. The attac…
- CVE-2025-12930MEDIUMCVSS 6.3EG 6.32025-11-10
A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /view-ticket.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remo…
- CVE-2025-12931MEDIUMCVSS 6.3EG 6.32025-11-10
A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/edit-orders.php. The manipulation of the argument ID results in sql injection. It is poss…
- CVE-2025-12932MEDIUMCVSS 4.7EG 4.72025-11-10
A vulnerability was determined in SourceCodester Baby Care System 1.0. Affected by this issue is some unknown functionality of the file /admin.php?id=inbox. This manipulation of the argument msgid causes sql injection. The attack can be in…
- CVE-2025-12933MEDIUMCVSS 6.3EG 6.32025-11-10
A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatewelcome.php?id=siteoptions&action=welcome. Such manipulation of the argument roleid leads to sql injection. The attack c…
- CVE-2025-12938HIGHCVSS 7.3EG 7.32025-11-10
A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknown functionality of the file /process_login.php. The manipulation of the argument keywords leads to sql injection. The a…
- CVE-2025-12939MEDIUMCVSS 6.3EG 6.32025-11-10
A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of the argument candName results in sql injec…
- CVE-2025-13057MEDIUMCVSS 6.3EG 6.32025-11-12
A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_student. The manipulation of the argument ID leads to sql injection. The attack may be…
- CVE-2025-13059MEDIUMCVSS 6.3EG 6.32025-11-12
A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown function of the file /manage_career.php. This manipulation of the argument ID causes sql injection. Remote exploitation of th…
- CVE-2025-13060HIGHCVSS 7.3EG 7.32025-11-12
A security vulnerability has been detected in SourceCodester Survey Application System 1.0. This affects an unknown function of the file /view_survey.php. Such manipulation of the argument ID leads to sql injection. The attack can be execu…
- CVE-2025-13075MEDIUMCVSS 4.7EG 4.72025-11-12
A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/usersettingdel.php. Performing manipulation of the argument eid results in sql injection. Remote exploitation of th…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →