CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 77 of 105
- CVE-2025-8327CRITICALCVSS 9.8EG 9.82025-07-30
A vulnerability classified as critical was found in code-projects Exam Form Submission 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_s8.php. The manipulation of the argument ID leads to sql injec…
- CVE-2025-8328CRITICALCVSS 9.8EG 9.82025-07-30
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument USN leads to sql …
- CVE-2025-8329CRITICALCVSS 9.8EG 9.82025-07-30
A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an unknown part of the file /filter3.php. The manipulation of the argument company leads to sql injection. It is possible to…
- CVE-2025-8330CRITICALCVSS 9.8EG 9.82025-07-30
A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit1.php. The manipulation of the argument sno leads to sql injection. The attack can …
- CVE-2025-8331CRITICALCVSS 9.8EG 9.82025-07-30
A vulnerability was found in code-projects Online Farm System 1.0 and classified as critical. This issue affects some unknown processing of the file /forgot_pass.php. The manipulation of the argument email leads to sql injection. The attac…
- CVE-2025-8332CRITICALCVSS 9.8EG 9.82025-07-30
A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /register.php. The manipulation of the argument Username leads to sql injection. It is possi…
- CVE-2025-8333CRITICALCVSS 9.8EG 9.82025-07-30
A vulnerability was found in code-projects Online Farm System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /categoryvalue.php. The manipulation of the argument Value leads to…
- CVE-2025-8334CRITICALCVSS 9.8EG 9.82025-07-30
A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ajax.php?action=delete_recruitment_status. The manipula…
- CVE-2025-8336CRITICALCVSS 9.8EG 9.82025-07-30
A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=save_user. The manipulation of the argument ID leads to sql …
- CVE-2025-8338CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability was found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /adminac.php. The manipulation of the argument ID leads to sql injection. T…
- CVE-2025-8339CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the file /student_login.php. The manipulation of the argument user_name/password leads …
- CVE-2025-8345CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability classified as critical was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this vulnerability is the function delete_user of the file crm/WeiXinApp/yunzhijia/yunzhijiaApi.php. The m…
- CVE-2025-8347MEDIUMCVSS 6.5EG 6.52025-07-31
A vulnerability, which was classified as critical, was found in Kehua Charging Pile Cloud Platform 1.0. This affects an unknown part of the file /sys/task/findAllTask. The manipulation leads to sql injection. It is possible to initiate the…
- CVE-2025-8371CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability has been found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/update_s5.php. The manipulation of the argument credits lead…
- CVE-2025-8372CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/update_s7.php. The manipulation of the argument credits leads to sql in…
- CVE-2025-8373CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability was found in code-projects Vehicle Management 1.0. It has been classified as critical. This affects an unknown part of the file /print.php. The manipulation of the argument sno leads to sql injection. It is possible to init…
- CVE-2025-8374CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability was found in code-projects Vehicle Management 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /addcompany.php. The manipulation of the argument company leads to sql injection. The …
- CVE-2025-8375CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability was found in code-projects Vehicle Management 1.0. It has been rated as critical. This issue affects some unknown processing of the file /addvehicle.php. The manipulation of the argument vehicle leads to sql injection. The …
- CVE-2025-8376CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability classified as critical has been found in code-projects Vehicle Management 1.0. Affected is an unknown function of the file /updatebal.php. The manipulation of the argument company leads to sql injection. It is possible to l…
- CVE-2025-8378CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability was found in Campcodes Online Hotel Reservation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/index.php of the component Login. The manipulation of the ar…
- CVE-2025-8381HIGHCVSS 8.8EG 8.82025-07-31
A vulnerability, which was classified as critical, has been found in Campcodes Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /add_reserve.php. The manipulation of the argument room_id leads to …
- CVE-2025-8382HIGHCVSS 8.8EG 8.82025-07-31
A vulnerability, which was classified as critical, was found in Campcodes Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/edit_room.php. The manipulation of the argument room_id leads to sql injectio…
- CVE-2025-8407CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability, which was classified as critical, has been found in code-projects Vehicle Management 1.0. This issue affects some unknown processing of the file /filter2.php. The manipulation of the argument from leads to sql injection. T…
- CVE-2025-8408CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. Affected is an unknown function of the file /filter1.php. The manipulation of the argument vehicle leads to sql injection. It is possible…
- CVE-2025-8409CRITICALCVSS 9.8EG 9.82025-07-31
A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /filter.php. The manipulation of the argument from leads to sql injec…
- CVE-2025-8431CRITICALCVSS 9.8EG 9.82025-08-01
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/add-boat.php. The manipulation of the argument boatname leads to sql injection. The…
- CVE-2025-8436CRITICALCVSS 9.8EG 9.82025-08-01
A vulnerability was found in projectworlds Online Admission System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /viewdoc.php. The manipulation of the argument ID leads to sql injectio…
- CVE-2025-8437CRITICALCVSS 9.8EG 9.82025-08-01
A vulnerability classified as critical has been found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userregistration.php. The manipulation of the argument email leads to sql injection. It is possible to i…
- CVE-2025-8438CRITICALCVSS 9.8EG 9.82025-08-01
A vulnerability classified as critical was found in code-projects Wazifa System 1.0. This vulnerability affects unknown code of the file /controllers/postpublish.php. The manipulation of the argument post leads to sql injection. The attack…
- CVE-2025-8439CRITICALCVSS 9.8EG 9.82025-08-01
A vulnerability, which was classified as critical, has been found in code-projects Wazifa System 1.0. This issue affects some unknown processing of the file /controllers/updatesettings.php. The manipulation of the argument Password leads t…
- CVE-2025-8441CRITICALCVSS 9.8EG 9.82025-08-01
A vulnerability, which was classified as critical, was found in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /pharsignup.php. The manipulation of the argument phuname leads to sql injection. It is po…
- CVE-2025-8442CRITICALCVSS 9.8EG 9.82025-08-01
A vulnerability has been found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cussignup.php. The manipulation of the argument uname leads to sq…
- CVE-2025-8443CRITICALCVSS 9.8EG 9.82025-08-01
A vulnerability was found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. Th…
- CVE-2025-8466CRITICALCVSS 9.8EG 9.82025-08-02
A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /forgot_passfarmer.php. The manipulation of the argument email leads to sql injection. It is…
- CVE-2025-8467CRITICALCVSS 9.8EG 9.82025-08-02
A vulnerability was found in code-projects Wazifa System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /controllers/regcontrol.php. The manipulation of the argument Username l…
- CVE-2025-8468CRITICALCVSS 9.8EG 9.82025-08-02
A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /controllers/reset.php. The manipulation of the argument email leads to sql injec…
- CVE-2025-8469CRITICALCVSS 9.8EG 9.82025-08-02
A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/deletegallery.php. The manipulation of the argument ID leads to sql injection. It …
- CVE-2025-8470CRITICALCVSS 9.8EG 9.82025-08-02
A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/deleteroom.php. The manipulation of the argument ID leads to sql injection. …
- CVE-2025-8471CRITICALCVSS 9.8EG 9.82025-08-02
A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file /adminlogin.php. The manipulation of the argument a_id leads to sql inje…
- CVE-2025-8493CRITICALCVSS 9.8EG 9.82025-08-02
A vulnerability classified as critical was found in code-projects Intern Membership Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_student_query.php. The manipulation of the argument ID leads to sql …
- CVE-2025-8494CRITICALCVSS 9.8EG 9.82025-08-03
A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /admin/delete_student.php. The manipulation of the argument …
- CVE-2025-8495CRITICALCVSS 9.8EG 9.82025-08-03
A vulnerability, which was classified as critical, was found in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /admin/edit_admin_query.php. The manipulation of the argument Username leads…
- CVE-2025-8496CRITICALCVSS 9.8EG 9.82025-08-03
A vulnerability has been found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /viewform.php. The manipulation of the argument ID leads to sql …
- CVE-2025-8497CRITICALCVSS 9.8EG 9.82025-08-03
A weakness has been identified in code-projects Online Medicine Guide 1.0. This affects an unknown part of the file /cusfindphar2.php. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is poss…
- CVE-2025-8498CRITICALCVSS 9.8EG 9.82025-08-03
A security vulnerability has been detected in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /cart/index.php. Such manipulation of the argument uname leads to sql injection. The attack can be e…
- CVE-2025-8499CRITICALCVSS 9.8EG 9.82025-08-03
A vulnerability was found in code-projects Online Medicine Guide 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cusfindambulence2.php. The manipulation of the argument Search leads to sql inject…
- CVE-2025-8500HIGHCVSS 8.8EG 8.82025-08-03
A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /insert-and-view/action.php. The manipulation of the argument content le…
- CVE-2025-8502CRITICALCVSS 9.8EG 9.82025-08-03
A vulnerability classified as critical was found in code-projects Online Medicine Guide 1.0. Affected by this vulnerability is an unknown functionality of the file /changepass.php. The manipulation of the argument ups leads to sql injectio…
- CVE-2025-8503CRITICALCVSS 9.8EG 9.82025-08-03
A vulnerability, which was classified as critical, has been found in code-projects Online Medicine Guide 1.0. Affected by this issue is some unknown functionality of the file /adaddmed.php. The manipulation of the argument mname leads to s…
- CVE-2025-8518HIGHCVSS 7.2EG 7.22025-08-04
A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function Save of the file admin/controller/editor/code.php of the component Code Editor. The manipulation leads to code injection…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →