CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,223 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 55 of 105
- CVE-2025-3217HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /registration.php. The manipulation of the argument emailid leads to sql injection…
- CVE-2025-3220HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard.php. The manipulation of the argument Category leads…
- CVE-2025-3229MEDIUMCVSS 4.7EG 4.72025-04-04
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /edit-subadmin.php. The manipulation of the argument fullname leads to sql i…
- CVE-2025-3231HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file /aboutus.php. The manipulation of the argument pagetitle/pagedes leads to sql injectio…
- CVE-2025-3235MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/profile.php. The manipulation of the argument adminname/contactnumber leads to …
- CVE-2025-3238HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability classified as critical has been found in PHPGurukul Online Fire Reporting System 1.2. Affected is an unknown function of the file /search-request.php. The manipulation of the argument searchdata leads to sql injection. It i…
- CVE-2025-3239HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. Affected by this vulnerability is an unknown functionality of the file /admin/edit-guard-detail.php. The manipulation of the argument editid l…
- CVE-2025-32390HIGHCVSS 8.5EG 8.52025-05-12
EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles leads to complete page defacement imitating the login page. Authenticated users with the read …
- CVE-2025-3240HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability, which was classified as critical, has been found in PHPGurukul Online Fire Reporting System 1.2. Affected by this issue is some unknown functionality of the file /admin/search.php. The manipulation of the argument searchda…
- CVE-2025-3242MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability has been found in PHPGurukul e-Diary Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /search-result.php. The manipulation of the argument id/searchdata leads to sql inje…
- CVE-2025-3243MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dental_form.php. The manipulation of the argument itr_no/dental_no leads to…
- CVE-2025-3245MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability was found in itsourcecode Library Management System 1.0. It has been rated as critical. Affected by this issue is the function Search of the file library_management/src/Library_Management/Forgot.java. The manipulation of th…
- CVE-2025-3249MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to comma…
- CVE-2025-3258HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability classified as critical was found in PHPGurukul Old Age Home Management System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument searchdata leads to sql injection. The att…
- CVE-2025-3265HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-category.php. The manipulation of the argument Category leads to sql …
- CVE-2025-3267MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability, which was classified as critical, was found in qinguoyi TinyWebServer up to 1.0. This affects an unknown part of the file /http/http_conn.cpp. The manipulation of the argument name/password leads to sql injection. It is po…
- CVE-2025-32699LOWCVSS 2.1EG 2.12025-04-10
Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1; Parsoid: before 0.16.5, 0.19.2, 0.20.2.
- CVE-2025-32711CRITICALCVSS 9.3EG 9.32025-06-11
Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
- CVE-2025-3296MEDIUMCVSS 6.3EG 6.32025-04-05
A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=delete_customer. The manipulation of the argument ID l…
- CVE-2025-3299HIGHCVSS 7.3EG 7.32025-04-05
A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /appointment.php. The manipulation of the argument Name leads to sql injec…
- CVE-2025-3303MEDIUMCVSS 6.3EG 6.32025-04-05
A vulnerability, which was classified as critical, has been found in code-projects Patient Record Management System 1.0. Affected by this issue is some unknown functionality of the file /birthing_record.php. The manipulation of the argumen…
- CVE-2025-3304MEDIUMCVSS 6.3EG 6.32025-04-05
A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dental_not.php. The manipulation of the argument itr_no leads to sql injection. I…
- CVE-2025-3306HIGHCVSS 7.3EG 7.32025-04-06
A vulnerability was found in code-projects Blood Bank Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /don.php. The manipulation of the argument fullname leads to sql injection. The …
- CVE-2025-3307HIGHCVSS 7.3EG 7.32025-04-06
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /reset.php. The manipulation of the argument useremail leads to sql injection. It …
- CVE-2025-3308HIGHCVSS 7.3EG 7.32025-04-06
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /viewrequest.php. The manipulation of the argument ID lea…
- CVE-2025-3309HIGHCVSS 7.3EG 7.32025-04-06
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/campsdetails.php. The manipulation of the argument hospital…
- CVE-2025-3310HIGHCVSS 7.3EG 7.32025-04-06
A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the file /admin/delete.php. The manipulation of the argument Search leads to sql injection. It is poss…
- CVE-2025-3311HIGHCVSS 7.3EG 7.32025-04-06
A vulnerability classified as critical was found in PHPGurukul Men Salon Management System 1.0. This vulnerability affects unknown code of the file /admin/about-us.php. The manipulation of the argument pagetitle leads to sql injection. The…
- CVE-2025-3312HIGHCVSS 7.3EG 7.32025-04-06
A vulnerability, which was classified as critical, has been found in PHPGurukul Men Salon Management System 1.0. This issue affects some unknown processing of the file /admin/add-customer-services.php. The manipulation of the argument sids…
- CVE-2025-3313HIGHCVSS 7.3EG 7.32025-04-06
A vulnerability, which was classified as critical, was found in PHPGurukul Men Salon Management System 1.0. Affected is an unknown function of the file /admin/add-customer.php. The manipulation of the argument Name leads to sql injection. …
- CVE-2025-3314HIGHCVSS 7.3EG 7.32025-04-06
A vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /forgotpw.php. The manipulation of the argument sec…
- CVE-2025-3315HIGHCVSS 7.3EG 7.32025-04-06
A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view-report.php. The manipulation of the argument fromdate/to…
- CVE-2025-3316HIGHCVSS 7.3EG 7.32025-04-06
A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/search-invoices.php. The manipulation of the argument searchdata leads to…
- CVE-2025-3318MEDIUMCVSS 6.3EG 6.32025-04-06
A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected by this vulnerability is the function page of the file src/main/java/com/controller/Shangpinleix…
- CVE-2025-3323MEDIUMCVSS 6.3EG 6.32025-04-06
A vulnerability classified as critical was found in godcheese/code-projects Nimrod 0.8. Affected by this vulnerability is the function searchAllByName of the file ViewMenuCategoryRestController.java. The manipulation of the argument Name l…
- CVE-2025-3330HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability classified as critical was found in codeprojects Online Restaurant Management System 1.0. This vulnerability affects unknown code of the file /reservation_save.php. The manipulation of the argument first leads to sql inject…
- CVE-2025-3331HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability, which was classified as critical, has been found in codeprojects Online Restaurant Management System 1.0. This issue affects some unknown processing of the file /payment_save.php. The manipulation of the argument mode lead…
- CVE-2025-3332HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. Affected is an unknown function of the file /admin/menu_save.php. The manipulation of the argument menu leads to sql inje…
- CVE-2025-3333HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/menu_update.php. The manipulation of the argum…
- CVE-2025-3334HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/category_save.php. The manipulation of the argument Categ…
- CVE-2025-3335HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/category_update.php. The manipulation of the argument ID leads to sql in…
- CVE-2025-3336HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/member_save.php. The manipulation of the argument last leads to…
- CVE-2025-3337HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/member_update.php. The manipulation of the argument ID leads to…
- CVE-2025-3338HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability classified as critical has been found in codeprojects Online Restaurant Management System 1.0. Affected is an unknown function of the file /admin/user_save.php. The manipulation of the argument Name leads to sql injection. …
- CVE-2025-3339HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability classified as critical was found in codeprojects Online Restaurant Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user_update.php. The manipulation of the argument ID le…
- CVE-2025-3340HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability, which was classified as critical, has been found in codeprojects Online Restaurant Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/combo_update.php. The manipulation of the ar…
- CVE-2025-3341HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. This affects an unknown part of the file /admin/reservation_view.php. The manipulation of the argument ID leads to sql in…
- CVE-2025-3342HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/payment_save.php. The manipulation of the argument ID leads to sq…
- CVE-2025-3343HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/reservation_update.php. The manipulation of the argument ID leads t…
- CVE-2025-3344HIGHCVSS 7.3EG 7.32025-04-07
A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/assign_save.php. The manipulation of the argument ID leads to sql inj…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →