CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,983 vulnerabilities with CWE-74
CVE-2026-14732 HIGH
SourceCodester Class and Exam Timetabling System edit_exam.php sql injection
CVSS 7.3
CVE-2026-14731 MEDIUM
itsourcecode Hospital Management System patientreport.php sql injection
CVSS 6.3
CVE-2026-14730 MEDIUM
itsourcecode Hospital Management System patientprofile.php sql injection
CVSS 6.3
CVE-2026-14722 HIGH
tiddly-gittly TidGi-Desktop Git Repository Import loadWikiTiddlersWithSubWikis.ts code injection
CVSS 7.3
CVE-2026-14717 MEDIUM
itsourcecode Hospital Management System patientlogin.php sql injection
CVSS 6.3
CVE-2026-14713 HIGH
SourceCodester Pizzafy E-Commerce System ajax.php confirm_order sql injection
CVSS 7.3
CVE-2026-14706 MEDIUM
code-projects Online Examination Quiz Creation Feature update.php sql injection
CVSS 6.3
CVE-2026-14705 HIGH
code-projects Online Examination head.php sql injection
CVSS 7.3
CVE-2026-14703 MEDIUM
itsourcecode Hospital Management System patientorder.php sql injection
CVSS 6.3
CVE-2026-14701 MEDIUM
code-projects Internship Management System Password Change Endpoint change_password.php sql injection
CVSS 6.3
CVE-2026-14700 HIGH
code-projects Internship Management System Employer Login Endpoint login.php sql injection
CVSS 7.3
CVE-2026-14695 HIGH
SourceCodester Multi-Vendor Online Grocery Management System Registration Users.php save_client sql injection
CVSS 7.3
CVE-2026-14694 MEDIUM
SourceCodester Multi-Vendor Online Grocery Management System POST Parameter Master.php cancel_order sql injection
CVSS 6.3
CVE-2026-14692 MEDIUM
SourceCodester Multi-Vendor Online Grocery Management System POST Parameter Master.php save_shop_type sql injection
CVSS 6.3
CVE-2026-14691 MEDIUM
SourceCodester Multi-Vendor Online Grocery Management System Setting SystemSettings.php update_settings_info code injection
CVSS 6.3
CVE-2026-14689 MEDIUM
CodeAstro Apartment Visitor Management System add-apartment.php sql injection
CVSS 6.3
CVE-2026-14688 HIGH
itsourcecode Online Hotel Management System login.php sql injection
CVSS 7.3
CVE-2026-14660 HIGH
code-projects Online Job Portal login.php sql injection
CVSS 7.3
CVE-2026-14659 MEDIUM
itsourcecode Hospital Management System patientappointment.php sql injection
CVSS 6.3
CVE-2026-14658 MEDIUM
code-projects Assessment Management marking-scheme.php sql injection
CVSS 6.3
CVE-2026-14657 MEDIUM
code-projects Assessment Management Database Query marking-scheme.php sql injection
CVSS 6.3
CVE-2026-14654 HIGH
SourceCodester Simple and Nice Shopping Cart Script girlsproductdeletequery.php sql injection
CVSS 7.3
CVE-2026-14653 HIGH
SourceCodester Simple and Nice Shopping Cart Script mensproductdeletequery.php sql injection
CVSS 7.3
CVE-2026-14652 HIGH
SourceCodester Simple and Nice Shopping Cart Script Admin Login login.php sql injection
CVSS 7.3
CVE-2026-14649 HIGH
code-projects Online Voting System saveVote.php test_input sql injection
CVSS 7.3
Details
Vulnerabilities 4,983
Exploit Likelihood High