CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,984 vulnerabilities with CWE-74
CVE-2026-6599 MEDIUM
langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injection
CVSS 6.3
CVE-2026-6595 HIGH
ProjectsAndPrograms School Management System HTTP GET Parameter buslocation.php sql injection
CVSS 7.3
CVE-2026-6576 MEDIUM
liangliangyy DjangoBlog WeChat Bot commonapi.py CommandHandler command injection
CVSS 6.3
CVE-2026-6562 HIGH
dameng100 muucmf index.html getListByPage sql injection
CVSS 7.3
CVE-2026-6490 HIGH
QueryMine sms GET Request Parameter deletecourse.php sql injection
CVSS 7.3
CVE-2026-6488 MEDIUM
QueryMine sms GET Request Parameter editcourse.php sql injection
CVSS 6.3
CVE-2026-5797 MEDIUM
Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields
CVSS 5.3
CVE-2026-39419 LOW
MaxKB: Sandbox Result Validation Bypass via Tool Output Spoofing
CVSS 3.1
CVE-2026-6219 MEDIUM
aandrew-me ytDownloader Compressor Feature compressor.js child_process.exec command injection
CVSS 5.3
CVE-2026-6202 MEDIUM
code-projects Easy Blog Site post.php sql injection
CVSS 6.3
CVE-2026-6193 HIGH
PHPGurukul Daily Expense Tracking System register.php sql injection
CVSS 7.3
CVE-2026-6191 MEDIUM
itsourcecode Construction Management System equipments.php sql injection
CVSS 6.3
CVE-2026-6190 MEDIUM
itsourcecode Construction Management System employees.php sql injection
CVSS 6.3
CVE-2026-6189 HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
CVSS 7.3
CVE-2026-6188 HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
CVSS 7.3
CVE-2026-6187 HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
CVSS 7.3
CVE-2026-6183 HIGH
code-projects Simple Content Management System index.php sql injection
CVSS 7.3
CVE-2026-6182 HIGH
code-projects Simple Content Management System login.php sql injection
CVSS 7.3
CVE-2026-6167 HIGH
code-projects Faculty Management System subject-print.php sql injection
CVSS 7.3
CVE-2026-6166 HIGH
code-projects Vehicle Showroom Management System UpdateVehicleFunction.php sql injection
CVSS 7.3
CVE-2026-6165 HIGH
code-projects Vehicle Showroom Management System Login_check.php sql injection
CVSS 7.3
CVE-2026-6164 HIGH
code-projects Lost and Found Thing Management addcat.php sql injection
CVSS 7.3
CVE-2026-6163 HIGH
code-projects Lost and Found Thing Management catageory.php sql injection
CVSS 7.3
CVE-2026-6161 HIGH
code-projects Simple ChatBox Endpoint insert.php sql injection
CVSS 7.3
CVE-2026-6153 HIGH
code-projects Vehicle Showroom Management System StaffDetailsFunction.php sql injection
CVSS 7.3
Details
Vulnerabilities 4,984
Exploit Likelihood High