CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,223 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 68 of 105
- CVE-2025-6321HIGHCVSS 8.8EG 8.82025-06-20
A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument sadm…
- CVE-2025-6322CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /visit.php. The manipulation of the argument gname leads to sql injection…
- CVE-2025-6323CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been classified as critical. This affects an unknown part of the file /enrollment.php. The manipulation of the argument fathername leads to sql injection. It …
- CVE-2025-6330CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability classified as critical has been found in PHPGurukul Directory Management System 1.0. Affected is an unknown function of the file /searchdata.php. The manipulation of the argument searchdata leads to sql injection. It is pos…
- CVE-2025-6331HIGHCVSS 8.8EG 8.82025-06-20
A vulnerability classified as critical was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search-directory.php. The manipulation of the argument searchdata…
- CVE-2025-6332HIGHCVSS 8.8EG 8.82025-06-20
A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /admin/manage-directory.php. The manipulation of the argument…
- CVE-2025-6333HIGHCVSS 8.8EG 8.82025-06-20
A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to sql injectio…
- CVE-2025-6335HIGHCVSS 7.2EG 7.22025-06-20
A vulnerability was found in DedeCMS up to 5.7.2 and classified as critical. This issue affects some unknown processing of the file /include/dedetag.class.php of the component Template Handler. The manipulation of the argument notes leads …
- CVE-2025-6339CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability was found in ponaravindb Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /func3.php. The manipulation of the argument username1 leads to sql in…
- CVE-2025-6342CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. This issue affects some unknown processing of the file /admin/admin_football.php. The manipulation of the argument pid leads to sql i…
- CVE-2025-6343CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_product.php. The manipulation of the argument pid leads to sql injection. It is p…
- CVE-2025-6344CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /contactus.php. The manipulation of the argument email leads to sql in…
- CVE-2025-6346CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability was found in SourceCodester Advance Charity Management System 1.0. It has been classified as critical. This affects an unknown part of the file /members/fundDetails.php. The manipulation of the argument m06 leads to sql inj…
- CVE-2025-6351CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability was found in itsourcecode Employee Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /editprofile.php. The manipulation of the argument emp1name leads to sql…
- CVE-2025-6354CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /function/customer_signup.php. The manipulation of the argument emai…
- CVE-2025-6355CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability has been found in SourceCodester Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/execeditroom.php. The manipulation of the argument userid leads to …
- CVE-2025-6356CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability was found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /addmem.php. The manipulation leads to sql injection. The attack may be initiate…
- CVE-2025-6357CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /paymentportal.php. The manipulation of the argument person leads to sql injection…
- CVE-2025-6358CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /saveorder.php. The manipulation of the argument ID leads…
- CVE-2025-6359CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /cashconfirm.php. The manipulation of the argument transactioncode…
- CVE-2025-6360CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability classified as critical has been found in code-projects Simple Pizza Ordering System 1.0. This affects an unknown part of the file /portal.php. The manipulation of the argument ID leads to sql injection. It is possible to in…
- CVE-2025-6361CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability affects unknown code of the file /adds.php. The manipulation of the argument userid leads to sql injection. The attack c…
- CVE-2025-6362CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability, which was classified as critical, has been found in code-projects Simple Pizza Ordering System 1.0. This issue affects some unknown processing of the file /editpro.php. The manipulation of the argument ID leads to sql inje…
- CVE-2025-6363CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /adding-exec.php. The manipulation of the argument ingname leads to sql injection. …
- CVE-2025-6364CRITICALCVSS 9.8EG 9.82025-06-20
A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /adduser-exec.php. The manipulation of the argument Usernam…
- CVE-2025-6394CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_reserve.php. The manipulation of the argum…
- CVE-2025-6403CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability was found in code-projects School Fees Payment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulation of the argument ID leads to sql injection. The …
- CVE-2025-6404CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability classified as critical has been found in Campcodes Online Teacher Record Management System 1.0. Affected is an unknown function of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injecti…
- CVE-2025-6405CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability classified as critical was found in Campcodes Online Teacher Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit-teacher-detail.php. The manipulation of the argum…
- CVE-2025-6406CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/forgot-password.php. The manipulation of the argume…
- CVE-2025-6407CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. This affects an unknown part of the file /user-login.php. The manipulation of the argument Username leads to sql injection. It…
- CVE-2025-6408CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /doctor/search.php. The manipulation of the argument searchdata leads to sql …
- CVE-2025-6409CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1 and classified as critical. This issue affects some unknown processing of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql in…
- CVE-2025-64099HIGHCVSS 8.1EG 8.12025-11-12
Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_supported" parameter is activated, it is possible, thanks to the "oidc-claims-extension.groovy" script, to inject the v…
- CVE-2025-6410HIGHCVSS 8.8EG 8.82025-06-21
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been classified as critical. Affected is an unknown function of the file /admin/edit-art-medium-detail.php. The manipulation of the argument editid leads to …
- CVE-2025-6411HIGHCVSS 8.8EG 8.82025-06-21
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/changepropic.php. The manipulation of the argument i…
- CVE-2025-6412HIGHCVSS 8.8EG 8.82025-06-21
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/changeimage.php. The manipulation of the argument editid lead…
- CVE-2025-6413HIGHCVSS 8.8EG 8.82025-06-21
A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.1. This affects an unknown part of the file /admin/changeimage1.php. The manipulation of the argument editid leads to sql injection. It is …
- CVE-2025-6414HIGHCVSS 8.8EG 8.82025-06-21
A vulnerability classified as critical was found in PHPGurukul Art Gallery Management System 1.1. This vulnerability affects unknown code of the file /admin/changeimage2.php. The manipulation of the argument editid leads to sql injection. …
- CVE-2025-6415HIGHCVSS 8.8EG 8.82025-06-21
A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.1. This issue affects some unknown processing of the file /admin/changeimage3.php. The manipulation of the argument editid lead…
- CVE-2025-6416HIGHCVSS 8.8EG 8.82025-06-21
A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected is an unknown function of the file /admin/changeimage4.php. The manipulation of the argument editid leads to sql injecti…
- CVE-2025-6417HIGHCVSS 8.8EG 8.82025-06-21
A vulnerability has been found in PHPGurukul Art Gallery Management System 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-artist.php. The manipulation of the argument award…
- CVE-2025-6418CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit_query_account.php. The manipulation of the argum…
- CVE-2025-6419CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit_room.php. The manipulation of the argument room_type leads to s…
- CVE-2025-6420CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add_room.php. The manipulation of the argument room_type le…
- CVE-2025-6421CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/add_account.php. The manipulation of the argument name/admi…
- CVE-2025-64428CRITICALCVSS 9.8EG 9.82025-11-20
Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection. A blacklist was added in the patch for version 2.10.14. However, JNDI injection remains possible via the iiop, corbana…
- CVE-2025-6446CRITICALCVSS 9.8EG 9.82025-06-21
A vulnerability, which was classified as critical, has been found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /clientdetails/admin/index.php. The manipulation of the argument Username …
- CVE-2025-6447CRITICALCVSS 9.8EG 9.82025-06-22
A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql …
- CVE-2025-6448CRITICALCVSS 9.8EG 9.82025-06-22
A vulnerability has been found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_room.php. The manipulation of the a…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →