CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,984 vulnerabilities with CWE-74
CVE-2026-7407 MEDIUM
SourceCodester Pizzafy Ecommerce System Setting ajax.php save_settings sql injection
CVSS 4.7
CVE-2026-7394 MEDIUM
SourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection
CVSS 4.7
CVE-2026-7392 MEDIUM
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injection
CVSS 6.3
CVE-2026-7391 MEDIUM
SourceCodester Pharmacy Sales and Inventory System ajax.php save_supplier sql injection
CVSS 6.3
CVE-2026-7389 HIGH
EyouCMS common.php GetSortData sql injection
CVSS 7.3
CVE-2026-7388 MEDIUM
EyouCMS Template File FilemanagerLogic.php editFile code injection
CVSS 4.7
CVE-2026-7316 HIGH
eiliyaabedini aider-mcp code_with_ai aider_mcp.py command injection
CVSS 7.3
CVE-2026-7293 MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php delete_category sql injection
CVSS 4.7
CVE-2026-7290 MEDIUM
JeecgBoot loadDict Endpoint SqlInjectionUtil.java SqlInjectionUtil sql injection
CVSS 6.3
CVE-2026-7283 MEDIUM
SourceCodester Pharmacy Sales and Inventory System ajax.php save_expired sql injection
CVSS 4.7
CVE-2026-7282 MEDIUM
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_expired sql injection
CVSS 4.7
CVE-2026-7268 MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php save_category sql injection
CVSS 6.3
CVE-2026-7267 MEDIUM
SourceCodester Pizzafy Ecommerce System view_prod.php sql injection
CVSS 6.3
CVE-2026-7266 MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php save_order sql injection
CVSS 6.3
CVE-2026-7265 MEDIUM
SourceCodester Pizzafy Ecommerce System index.php category sql injection
CVSS 6.3
CVE-2026-7264 MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_items sql injection
CVSS 6.3
CVE-2026-7229 MEDIUM
code-projects Coaching Management System POST reply.php sql injection
CVSS 6.3
CVE-2026-7228 HIGH
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
CVSS 7.3
CVE-2026-7227 HIGH
SourceCodester Pizzafy Ecommerce System ajax.php login sql injection
CVSS 7.3
CVE-2026-7226 HIGH
SourceCodester Pizzafy Ecommerce System ajax.php login2 sql injection
CVSS 7.3
CVE-2026-7225 HIGH
SourceCodester Pizzafy Ecommerce System ajax.php delete_menu sql injection
CVSS 7.3
CVE-2026-7224 HIGH
SourceCodester Pizzafy Ecommerce System ajax.php delete_cart sql injection
CVSS 7.3
CVE-2026-7215 HIGH
egtai gmx-vmd-mcp VMD Launch mcp_server.py launch_vmd_gui_tool command injection
CVSS 7.3
CVE-2026-7211 HIGH
dvladimirov MCP Git Search API mcp_server.py GitSearchRequest command injection
CVSS 7.3
CVE-2026-7206 HIGH
dubydu sqlite-mcp entry.py extract_to_json sql injection
CVSS 7.3
Details
Vulnerabilities 4,984
Exploit Likelihood High