CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,984 vulnerabilities with CWE-74
CVE-2026-6152 HIGH
code-projects Vehicle Showroom Management System StaffAddingFunction.php sql injection
CVSS 7.3
CVE-2026-6151 HIGH
code-projects Vehicle Showroom Management System PaymentStatusFunction.php sql injection
CVSS 7.3
CVE-2026-6149 HIGH
code-projects Vehicle Showroom Management System BookVehicleFunction.php sql injection
CVSS 7.3
CVE-2026-6148 HIGH
code-projects Vehicle Showroom Management System MonthTotalReportUpdateFunction.php sql injection
CVSS 7.3
CVE-2026-6142 HIGH
tushar-2223 Hotel Management System roomdelete.php sql injection
CVSS 7.3
CVE-2026-6125 MEDIUM
Dromara warm-flow Workflow Definition save-json SpelHelper.parseExpression code injection
CVSS 6.3
CVE-2026-6118 MEDIUM
AstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injection
CVSS 6.3
CVE-2026-6110 HIGH
FoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injection
CVSS 7.3
CVE-2026-6038 HIGH
code-projects Vehicle Showroom Management System RegisterCustomerFunction.php sql injection
CVSS 7.3
CVE-2026-6037 HIGH
code-projects Vehicle Showroom Management System AddVehicleFunction.php sql injection
CVSS 7.3
CVE-2026-6036 HIGH
code-projects Vehicle Showroom Management System VehicleDetailsFunction.php sql injection
CVSS 7.3
CVE-2026-6033 MEDIUM
CodeAstro Online Classroom updatedetailsfromstudent.php sql injection
CVSS 6.3
CVE-2026-6031 HIGH
code-projects Simple IT Discussion Forum add-category-function.php sql injection
CVSS 7.3
CVE-2026-6030 MEDIUM
itsourcecode Construction Management System del1.php sql injection
CVSS 6.3
CVE-2026-6010 MEDIUM
CodeAstro Online Classroom takeassessment2.php sql injection
CVSS 6.3
CVE-2026-6007 MEDIUM
itsourcecode Construction Management System del.php sql injection
CVSS 6.3
CVE-2026-6006 MEDIUM
code-projects Patient Record Management System edit_hpatient.php sql injection
CVSS 6.3
CVE-2026-6005 MEDIUM
code-projects Patient Record Management System hematology_print.php sql injection
CVSS 6.3
CVE-2026-6004 HIGH
code-projects Simple IT Discussion Forum delete-category.php sql injection
CVSS 7.3
CVE-2026-5985 HIGH
code-projects Simple IT Discussion Forum crud.php sql injection
CVSS 7.3
CVE-2026-5970 HIGH
FoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injection
CVSS 7.3
CVE-2026-5961 HIGH
code-projects Simple IT Discussion Forum topic-details.php sql injection
CVSS 7.3
CVE-2026-5848 MEDIUM
jeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injection
CVSS 4.7
CVE-2026-5840 MEDIUM
PHPGurukul News Portal Project check_availability.php sql injection
CVSS 4.7
CVE-2026-5839 MEDIUM
PHPGurukul News Portal Project add-subcategory.php sql injection
CVSS 4.7
Details
Vulnerabilities 4,984
Exploit Likelihood High