CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,984 vulnerabilities with CWE-74
CVE-2026-6152
HIGH
code-projects Vehicle Showroom Management System StaffAddingFunction.php sql injection
CVSS 7.3
CVE-2026-6151
HIGH
code-projects Vehicle Showroom Management System PaymentStatusFunction.php sql injection
CVSS 7.3
CVE-2026-6149
HIGH
code-projects Vehicle Showroom Management System BookVehicleFunction.php sql injection
CVSS 7.3
CVE-2026-6148
HIGH
code-projects Vehicle Showroom Management System MonthTotalReportUpdateFunction.php sql injection
CVSS 7.3
CVE-2026-6142
HIGH
tushar-2223 Hotel Management System roomdelete.php sql injection
CVSS 7.3
CVE-2026-6125
MEDIUM
Dromara warm-flow Workflow Definition save-json SpelHelper.parseExpression code injection
CVSS 6.3
CVE-2026-6118
MEDIUM
AstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injection
CVSS 6.3
CVE-2026-6110
HIGH
FoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injection
CVSS 7.3
CVE-2026-6038
HIGH
code-projects Vehicle Showroom Management System RegisterCustomerFunction.php sql injection
CVSS 7.3
CVE-2026-6037
HIGH
code-projects Vehicle Showroom Management System AddVehicleFunction.php sql injection
CVSS 7.3
CVE-2026-6036
HIGH
code-projects Vehicle Showroom Management System VehicleDetailsFunction.php sql injection
CVSS 7.3
CVE-2026-6033
MEDIUM
CodeAstro Online Classroom updatedetailsfromstudent.php sql injection
CVSS 6.3
CVE-2026-6031
HIGH
code-projects Simple IT Discussion Forum add-category-function.php sql injection
CVSS 7.3
CVE-2026-6030
MEDIUM
itsourcecode Construction Management System del1.php sql injection
CVSS 6.3
CVE-2026-6010
MEDIUM
CodeAstro Online Classroom takeassessment2.php sql injection
CVSS 6.3
CVE-2026-6007
MEDIUM
itsourcecode Construction Management System del.php sql injection
CVSS 6.3
CVE-2026-6006
MEDIUM
code-projects Patient Record Management System edit_hpatient.php sql injection
CVSS 6.3
CVE-2026-6005
MEDIUM
code-projects Patient Record Management System hematology_print.php sql injection
CVSS 6.3
CVE-2026-6004
HIGH
code-projects Simple IT Discussion Forum delete-category.php sql injection
CVSS 7.3
CVE-2026-5985
HIGH
code-projects Simple IT Discussion Forum crud.php sql injection
CVSS 7.3
CVE-2026-5970
HIGH
FoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injection
CVSS 7.3
CVE-2026-5961
HIGH
code-projects Simple IT Discussion Forum topic-details.php sql injection
CVSS 7.3
CVE-2026-5848
MEDIUM
jeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injection
CVSS 4.7
CVE-2026-5840
MEDIUM
PHPGurukul News Portal Project check_availability.php sql injection
CVSS 4.7
CVE-2026-5839
MEDIUM
PHPGurukul News Portal Project add-subcategory.php sql injection
CVSS 4.7
Details
Vulnerabilities
4,984
Exploit Likelihood
High