CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,217 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 43 of 105
- CVE-2025-13076MEDIUMCVSS 4.7EG 4.72025-11-12
A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/usersetting.php. Executing manipulation of the argument usname can lead to sql injection. The attack can be ex…
- CVE-2025-13121HIGHCVSS 7.3EG 7.32025-11-13
A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/app/Http/Controllers/Front/StoreController.php of the component API Endpoint. Such manipulation of the argument lng/lat …
- CVE-2025-13122HIGHCVSS 7.3EG 7.32025-11-13
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppointment of the file /php/api_patient_checkin.php. Performing manipulation of the argument …
- CVE-2025-13123MEDIUMCVSS 6.3EG 6.32025-11-13
A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the file /user/portal/get_firstdate.php. Executing manipulation of the argument uid can lead to sql injection. It is possibl…
- CVE-2025-13168MEDIUMCVSS 6.3EG 6.32025-11-14
A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the file ury/ury/api/pos_extend.py. This manipulation of the argument search_term causes sql injection. Remote exploitation o…
- CVE-2025-13169HIGHCVSS 7.3EG 7.32025-11-14
A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /add_query_reserve.php. Such manipulation of the argument room_id leads to sql inje…
- CVE-2025-13170HIGHCVSS 7.3EG 7.32025-11-14
A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/edit_account.php. Performing a manipulation of the argument admin_id results in sql inj…
- CVE-2025-13171MEDIUMCVSS 6.3EG 6.32025-11-14
A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit is publi…
- CVE-2025-13172MEDIUMCVSS 6.3EG 6.32025-11-14
A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/view-member-report.php. Performing a manipulation of the argument ID results in sql injection. The attack may be…
- CVE-2025-13178LOWCVSS 3.5EG 3.52025-11-14
A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20250728. This vulnerability affects unknown code of the file /edit_profile of the component User Profile Handler. This manipulation of the argument first_name/last_name causes basi…
- CVE-2025-13180LOWCVSS 3.5EG 3.52025-11-14
A vulnerability was found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. Impacted is an unknown function of the file /edit_profile. Performing manipulation of the argument first_name/last_n…
- CVE-2025-13201HIGHCVSS 7.3EG 7.32025-11-15
A vulnerability was identified in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Username leads to sql injection. The attack may…
- CVE-2025-13203HIGHCVSS 7.3EG 7.32025-11-15
A weakness has been identified in code-projects Simple Cafe Ordering System 1.0. This vulnerability affects unknown code of the file /addmem.php. Executing manipulation of the argument studentnum can lead to sql injection. It is possible t…
- CVE-2025-13208MEDIUMCVSS 6.3EG 6.32025-11-15
A security flaw has been discovered in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. The impacted element is an unknown function of the file controller/api/hotelList.php. The manipulation of the argument subjec…
- CVE-2025-13210MEDIUMCVSS 4.7EG 4.72025-11-15
A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=add. Such manipulation of the argument PROMODEL leads to sql injection.…
- CVE-2025-13233HIGHCVSS 7.3EG 7.32025-11-16
A vulnerability has been found in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /index.php?q=single-item. Such manipulation of the argument ID leads to sql injection. The attack may b…
- CVE-2025-13234MEDIUMCVSS 6.3EG 6.32025-11-16
A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function of the file /index.php?q=product. Performing manipulation of the argument PROID results in sql injection. It is possible…
- CVE-2025-13235HIGHCVSS 7.3EG 7.32025-11-16
A vulnerability was determined in itsourcecode Inventory Management System 1.0. This affects an unknown function of the file /admin/login.php. Executing manipulation of the argument user_email can lead to sql injection. It is possible to l…
- CVE-2025-13236MEDIUMCVSS 6.3EG 6.32025-11-16
A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be…
- CVE-2025-13237HIGHCVSS 7.3EG 7.32025-11-16
A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of the file /LogSignModal.PHP. The manipulation of the argument U_USERNAME results in sql injection. The attack can be lau…
- CVE-2025-13240HIGHCVSS 7.3EG 7.32025-11-16
A vulnerability was detected in code-projects Student Information System 2.0. This affects an unknown part of the file /searchquery.php. Performing manipulation of the argument s results in sql injection. Remote exploitation of the attack …
- CVE-2025-13241HIGHCVSS 7.3EG 7.32025-11-16
A flaw has been found in code-projects Student Information System 2.0. This vulnerability affects unknown code of the file /index.php. Executing manipulation of the argument Username can lead to sql injection. The attack can be executed re…
- CVE-2025-13242HIGHCVSS 7.3EG 7.32025-11-16
A vulnerability has been found in code-projects Student Information System 2.0. This issue affects some unknown processing of the file /register.php. The manipulation leads to sql injection. The attack is possible to be carried out remotel…
- CVE-2025-13243MEDIUMCVSS 6.3EG 6.32025-11-16
A vulnerability was found in code-projects Student Information System 2.0. Impacted is an unknown function of the file /editprofile.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has be…
- CVE-2025-13247HIGHCVSS 7.3EG 7.32025-11-16
A security flaw has been discovered in PHPGurukul Tourism Management System 1.0. The affected element is an unknown function of the file /admin/user-bookings.php. The manipulation of the argument uid results in sql injection. It is possibl…
- CVE-2025-13248HIGHCVSS 7.3EG 7.32025-11-16
A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is an unknown function of the file /php/api_patient_schedule.php. This manipulation of the argument appointmentID caus…
- CVE-2025-13251MEDIUMCVSS 6.3EG 6.32025-11-16
A flaw has been found in WeiYe-Jing datax-web up to 2.1.2. Affected is an unknown function. Executing manipulation can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
- CVE-2025-13253MEDIUMCVSS 6.3EG 6.32025-11-17
A vulnerability was determined in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /add_librarian.php. This manipulation of the argument Username causes sql injection. The attack is possible to…
- CVE-2025-13254MEDIUMCVSS 6.3EG 6.32025-11-17
A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /add_member.php. Such manipulation of the argument roll_number leads to sql injection. The attack m…
- CVE-2025-13255MEDIUMCVSS 6.3EG 6.32025-11-17
A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. This issue affects some unknown processing of the file /book_search.php. Performing a manipulation of the argument book_pub/book_title results in …
- CVE-2025-13256MEDIUMCVSS 6.3EG 6.32025-11-17
A weakness has been identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrow.php. Executing a manipulation of the argument roll_number can lead to sql injection. It is possible…
- CVE-2025-13257HIGHCVSS 7.3EG 7.32025-11-17
A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /admin/user/index.php?view=edit. The manipulation of the argument ID leads to sql injection…
- CVE-2025-13259MEDIUMCVSS 6.3EG 6.32025-11-17
A flaw has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /manufacturer/edit_unit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. T…
- CVE-2025-13260MEDIUMCVSS 6.3EG 6.32025-11-17
A vulnerability has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /manufacturer/edit_product.php. Such manipulation of the argument cmbProductUnit leads to sql injection. The attack ma…
- CVE-2025-13263MEDIUMCVSS 6.3EG 6.32025-11-17
A vulnerability was identified in SourceCodester Online Magazine Management System 1.0. Affected by this issue is some unknown functionality of the file /categories.php. The manipulation of the argument c leads to sql injection. The attack…
- CVE-2025-13264MEDIUMCVSS 6.3EG 6.32025-11-17
A security flaw has been discovered in SourceCodester Online Magazine Management System 1.0. This affects an unknown part of the file /view_magazine.php. The manipulation of the argument ID results in sql injection. The attack may be perfo…
- CVE-2025-13267MEDIUMCVSS 6.3EG 6.32025-11-17
A vulnerability was detected in SourceCodester Dental Clinic Appointment Reservation System 1.0. Impacted is an unknown function of the file /success.php. Performing manipulation of the argument username/password results in sql injection. …
- CVE-2025-13268MEDIUMCVSS 6.3EG 6.32025-11-17
A flaw has been found in Dromara dataCompare up to 1.0.1. The affected element is the function DbConfig of the file src/main/java/com/vince/xq/project/system/dbconfig/service/DbconfigServiceImpl.java of the component JDBC URL Handler. Exec…
- CVE-2025-13269MEDIUMCVSS 6.3EG 6.32025-11-17
A vulnerability has been found in Campcodes School Fees Payment Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_payment. The manipulation of the argument ID leads to sql injection. The a…
- CVE-2025-13270MEDIUMCVSS 6.3EG 6.32025-11-17
A vulnerability was found in Campcodes School Fees Payment Management System 1.0. This affects an unknown function of the file /ajax.php?action=save_course. The manipulation of the argument ID results in sql injection. The attack may be la…
- CVE-2025-13271HIGHCVSS 7.3EG 7.32025-11-17
A vulnerability was determined in Campcodes School Fees Payment Management System 1.0. This impacts an unknown function of the file /ajax.php?action=login. This manipulation of the argument Username causes sql injection. Remote exploitatio…
- CVE-2025-13272HIGHCVSS 7.3EG 7.32025-11-17
A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Affected is an unknown function of the file /manage_course.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed …
- CVE-2025-13273MEDIUMCVSS 6.3EG 6.32025-11-17
A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_payment. Performing a manipulation of the argument I…
- CVE-2025-13274MEDIUMCVSS 6.3EG 6.32025-11-17
A weakness has been identified in Campcodes School Fees Payment Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_fees. Executing a manipulation of the argument ID can lead to s…
- CVE-2025-13276HIGHCVSS 7.3EG 7.32025-11-17
A vulnerability was detected in g33kyrash Online-Banking-System up to 12dbfa690e5af649fb72d2e5d3674e88d6743455. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument Username results in sql inject…
- CVE-2025-13277HIGHCVSS 7.3EG 7.32025-11-17
A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of the file /friendsphoto.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remote…
- CVE-2025-13278MEDIUMCVSS 6.3EG 6.32025-11-17
A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrowed_book_search.php. Such manipulation of the argument datefrom/dateto leads to sql injection. The at…
- CVE-2025-13279MEDIUMCVSS 6.3EG 6.32025-11-17
A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function of the file /profilefriends.php. Performing manipulation of the argument ID results in sql injection. The attack may be…
- CVE-2025-13280HIGHCVSS 7.3EG 7.32025-11-17
A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. Executing a manipulation of the argument Username can lead to sql injection…
- CVE-2025-13285HIGHCVSS 7.3EG 7.32025-11-17
A vulnerability was identified in itsourcecode Online Voting System 1.0. The affected element is an unknown function of the file /login.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remo…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →