CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,984 vulnerabilities with CWE-74
CVE-2026-8344 MEDIUM
D-Link DIR-816 formDMZ.cgi sub_445E7C command injection
CVSS 6.3
CVE-2026-8231 MEDIUM
CodeAstro Online Catering Ordering System deleteorder.php sql injection
CVSS 6.3
CVE-2026-8211 MEDIUM
codelibs Fess JSP File AdminDesignAction.java update code injection
CVSS 4.7
CVE-2026-8210 MEDIUM
aandrew-me tgpt Update helper.go helper.Update command injection
CVSS 5.3
CVE-2026-41885 MEDIUM
Path traversal / URL injection via unsanitised lng/ns/projectId/version in i18next-locize-backend
CVSS 6.5
CVE-2026-8133 HIGH
zyx0814 FilePress Shares Filelist API admin.php sql injection
CVSS 7.3
CVE-2026-8132 HIGH
CodeAstro Leave Management System login.php sql injection
CVSS 7.3
CVE-2026-8131 HIGH
SourceCodester SUP Online Shopping replymsg.php sql injection
CVSS 7.3
CVE-2026-8130 HIGH
SourceCodester SUP Online Shopping message.php sql injection
CVSS 7.3
CVE-2026-8129 HIGH
SourceCodester SUP Online Shopping wishlist.php sql injection
CVSS 7.3
CVE-2026-8128 HIGH
SourceCodester SUP Online Shopping viewmsg.php sql injection
CVSS 7.3
CVE-2026-8126 HIGH
SourceCodester Comment System post_comment.php sql injection
CVSS 7.3
CVE-2026-8125 MEDIUM
code-projects Simple Chat System sendMessage.php sql injection
CVSS 6.3
CVE-2026-8114 MEDIUM
JeecgBoot JSON Object loadTreeData sql injection
CVSS 6.3
CVE-2026-26164 HIGH
M365 Copilot Information Disclosure Vulnerability
CVSS 7.5
CVE-2026-8098 HIGH
code-projects Feedback System checklogin.php sql injection
CVSS 7.3
CVE-2026-8097 MEDIUM
CodeAstro Online Classroom askquery.php sql injection
CVSS 6.3
CVE-2026-41691 MEDIUM
i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns
CVSS 6.5
CVE-2026-8083 HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php save_user sql injection
CVSS 7.3
CVE-2026-7833 HIGH
EFM ipTIME C200 ApplyRestore Endpoint iux_set.cgi sub_408F90 command injection
CVSS 7.2
CVE-2026-7822 MEDIUM
itsourcecode Courier Management System print_pdets.php sql injection
CVSS 6.3
CVE-2026-7812 HIGH
54yyyu code-mcp MCP Tool server.py git_operation command injection
CVSS 7.3
CVE-2026-7783 MEDIUM
CodeCanyon Perfex CRM Admin Kanban Endpoint AbstractKanban.php applySortQuery sql injection
CVSS 6.3
CVE-2026-7746 MEDIUM
SourceCodester Web-based Pharmacy Product Management System edit-admin.php sql injection
CVSS 6.3
CVE-2026-7745 MEDIUM
CodeAstro Online Classroom facultydetails sql injection
CVSS 6.3
Details
Vulnerabilities 4,984
Exploit Likelihood High