CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 83 of 105
- CVE-2026-0584MEDIUMCVSS 9.8EG 6.32026-01-05
A weakness has been identified in code-projects Online Product Reservation System 1.0. This issue affects some unknown processing of the file app/products/left_cart.php. This manipulation of the argument ID causes sql injection. Remote exp…
- CVE-2026-0585HIGHCVSS 9.8EG 7.32026-01-05
A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the file /order_view.php of the component GET Parameter Handler. Such manipulation of the argument transa…
- CVE-2026-0590MEDIUMCVSS 9.8EG 6.32026-01-05
A vulnerability was determined in code-projects Online Product Reservation System 1.0. The affected element is an unknown function of the file /app/checkout/delete.php of the component POST Parameter Handler. This manipulation of the argum…
- CVE-2026-0591MEDIUMCVSS 9.8EG 6.32026-01-05
A vulnerability was identified in code-projects Online Product Reservation System 1.0. The impacted element is an unknown function of the file /app/checkout/update.php of the component Cart Update Handler. Such manipulation of the argument…
- CVE-2026-0592HIGHCVSS 9.8EG 7.32026-01-05
A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This affects an unknown function of the file /handgunner-administrator/register_code.php of the component User Registration Handler. Performing a m…
- CVE-2026-0597MEDIUMCVSS 9.8EG 6.32026-01-05
A flaw has been found in Campcodes Supplier Management System 1.0. Affected by this issue is some unknown functionality of the file /retailer/edit_profile.php. This manipulation of the argument txtRetailerAddress causes sql injection. Remo…
- CVE-2026-0605HIGHCVSS 9.8EG 7.32026-01-05
A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Such manipulation of the argument username/password leads to sql injectio…
- CVE-2026-0606HIGHCVSS 9.8EG 7.32026-01-05
A vulnerability was detected in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /FrontEnd/Albums.php. Performing a manipulation of the argument ID results in sql injection. It is possib…
- CVE-2026-0607HIGHCVSS 9.8EG 7.32026-01-06
A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminViewSongs.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch t…
- CVE-2026-0641MEDIUMCVSS 8.8EG 6.32026-01-06
A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cstecgi.cgi. The manipulation of the argument UPLOAD_FILENAME leads to command injection. The…
- CVE-2026-0697MEDIUMCVSS 7.2EG 4.72026-01-08
A flaw has been found in code-projects Intern Membership Management System 1.0. The impacted element is an unknown function of the file /intern/admin/edit_admin.php. This manipulation of the argument admin_id causes sql injection. The atta…
- CVE-2026-0698MEDIUMCVSS 7.2EG 4.72026-01-08
A vulnerability has been found in code-projects Intern Membership Management System 1.0. This affects an unknown function of the file /intern/admin/edit_students.php. Such manipulation of the argument admin_id leads to sql injection. The a…
- CVE-2026-0699MEDIUMCVSS 7.2EG 4.72026-01-08
A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of the file /intern/admin/edit_activity.php. Performing a manipulation of the argument activity_id results in sql injectio…
- CVE-2026-0700HIGHCVSS 9.8EG 7.32026-01-08
A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/check_admin.php. Executing a manipulation of the argument Username can lead to sql injection…
- CVE-2026-0701MEDIUMCVSS 7.2EG 4.72026-01-08
A vulnerability was identified in code-projects Intern Membership Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /intern/admin/add_admin.php. The manipulation of the argument Username leads to…
- CVE-2026-0728MEDIUMCVSS 7.2EG 4.72026-01-08
A security vulnerability has been detected in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /intern/admin/delete_admin.php. Such manipulation of the argument admin_id leads to…
- CVE-2026-0729MEDIUMCVSS 7.2EG 4.72026-01-08
A vulnerability was detected in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /intern/admin/add_activity.php. Performing a manipulation of the argument Title results in sql injection. Re…
- CVE-2026-0732MEDIUMCVSS 9.8EG 6.32026-01-09
A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the argument path results in command injection. The attack may be performed from remote. The exp…
- CVE-2026-0733MEDIUMCVSS 8.8EG 6.32026-01-09
A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown function of the file /onlinecourse/admin/manage-students.php. This manipulation of the argument id/cid causes sql injection. …
- CVE-2026-0803MEDIUMCVSS 8.8EG 6.32026-01-09
A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the file /enroll.php. The manipulation of the argument studentregno/Pincode/session/department/level/course/sem results in…
- CVE-2026-0843MEDIUMCVSS 6.3EG 6.32026-01-11
A vulnerability has been found in jiujiujia/victor123/wxw850227 jjjfood and jjjshop_food up to 20260103. This vulnerability affects unknown code of the file /index.php/api/product.category/index. Such manipulation of the argument latitude …
- CVE-2026-0850MEDIUMCVSS 7.2EG 4.72026-01-11
A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /admin/delete_activity.php. Executing a manipulation of the argument activity_id can lead to sql injection…
- CVE-2026-0851HIGHCVSS 9.8EG 7.32026-01-12
A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/AdminAddUser.php. The manipulation of the argument txtusername leads to sql injection. Remote…
- CVE-2026-0852HIGHCVSS 9.8EG 7.32026-01-12
A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminUpdateUser.php. The manipulation of the argument ID results in sql injection. The a…
- CVE-2026-0864MEDIUMCVSS 4.1EG 4.12026-06-23
When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the writ…
- CVE-2026-0865MEDIUMCVSS 5.9EG 5.92026-01-20
User-controlled header names and values containing newlines can allow injecting HTTP headers.
- CVE-2026-0972HIGHCVSS 5.4EG 7.32026-04-21
HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.
- CVE-2026-10060CRITICALCVSS 9.8EG 9.82026-05-29
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to command injection. Remote exploitation of the…
- CVE-2026-10061CRITICALCVSS 9.8EG 9.82026-05-29
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. The attack can be executed remotely. The exploit…
- CVE-2026-10110HIGHCVSS 7.3EG 7.32026-05-30
A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument roll results in sql injection. The attack is possible t…
- CVE-2026-10111HIGHCVSS 7.3EG 7.32026-05-30
A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts an unknown function of the component Login Page. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remo…
- CVE-2026-10127MEDIUMCVSS 6.3EG 6.32026-05-30
A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This manipulation of the argument rootAPmac causes command inject…
- CVE-2026-10155MEDIUMCVSS 4.7EG 4.72026-05-30
A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accounts.php of the component Accounts Report…
- CVE-2026-10166MEDIUMCVSS 6.3EG 6.32026-05-31
A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. This manipulation of the argument rootAPmac causes command inj…
- CVE-2026-10170MEDIUMCVSS 6.3EG 6.32026-05-31
A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /vms/php/phone_0.php. This manipulation of the argument phone causes sql injection. The attack may be in…
- CVE-2026-10171MEDIUMCVSS 4.7EG 4.72026-05-31
A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. Such manipulation of the argument ID leads to sql injection. The attack may be launche…
- CVE-2026-10175MEDIUMCVSS 6.3EG 6.32026-05-31
A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a manipulation results in code injection. Remote …
- CVE-2026-10176MEDIUMCVSS 6.3EG 6.32026-05-31
A weakness has been identified in Aider-AI Aider 0.86.3. Affected by this issue is some unknown functionality of the component Code Generation Workflow. Executing a manipulation can lead to sql injection. The attack can be executed remotel…
- CVE-2026-10178HIGHCVSS 7.3EG 7.32026-05-31
A vulnerability was detected in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminEditAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be…
- CVE-2026-10180MEDIUMCVSS 6.3EG 6.32026-05-31
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation of the argument sysCmd leads to command injection. It is possible to launch the attack rem…
- CVE-2026-10182MEDIUMCVSS 6.3EG 6.32026-05-31
A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formWlanSetup of the file /goform/formWlanSetup. Executing a manipulation of the argument enrollee can lead to command injection. The attac…
- CVE-2026-10184HIGHCVSS 7.3EG 7.32026-05-31
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. …
- CVE-2026-10185HIGHCVSS 7.3EG 7.32026-05-31
A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote expl…
- CVE-2026-10186HIGHCVSS 7.3EG 7.32026-05-31
A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql i…
- CVE-2026-10193MEDIUMCVSS 6.3EG 6.32026-05-31
A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element is the function Query of the file ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\ComnController.java of the component ComnController. Performing a ma…
- CVE-2026-10202MEDIUMCVSS 6.3EG 6.32026-05-31
A vulnerability was identified in OFCMS 1.1.3. This issue affects the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemDictController.java of the component JSON Query Interface. The manipul…
- CVE-2026-10203MEDIUMCVSS 6.3EG 6.32026-05-31
A security flaw has been discovered in OFCMS 1.1.3. Impacted is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemParamController.java of the component JSON Query Interface. The manipula…
- CVE-2026-10204MEDIUMCVSS 6.3EG 6.32026-05-31
A weakness has been identified in OFCMS 1.1.3. The affected element is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SysUserController.java of the component JSON Query Interface. This mani…
- CVE-2026-10208HIGHCVSS 7.3EG 7.32026-06-01
A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be ex…
- CVE-2026-10209MEDIUMCVSS 6.3EG 6.32026-06-01
A vulnerability has been found in code-projects Online Hospital Management System 1.0. Affected is an unknown function of the file appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →