CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2025-47286 HIGH
Combodo iTop < 2.7.13 - Authenticated Remote Code Execution via Configuration Parameter
CVSS 7.2
CVE-2025-12939 MEDIUM
SourceCodester Interview Management System <1.0 - SQL Injection
CVSS 6.3
CVE-2025-12938 HIGH
Projectworlds Online Admission System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12933 MEDIUM
SourceCodester Baby Care System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-12932 MEDIUM
SourceCodester Baby Care System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12931 MEDIUM
SourceCodester Food Ordering System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-12930 MEDIUM
SourceCodester Food Ordering System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-12929 HIGH
SourceCodester Survey Application System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12928 HIGH
Code-projects Online Job Search Engine 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12927 MEDIUM
DedeBIZ < 6.3.2 - SQL Injection via archives_add.php flags[] Parameter
CVSS 4.7
CVE-2025-12926 MEDIUM
SourceCodester Farm Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-12921 MEDIUM
OpenClinica Community Edition <3.12.2/3.13 - XML Injection
CVSS 4.3
CVE-2025-12916 MEDIUM
Sangfor Operation And Maintenance Security Management System < 3.0.11 - Command Injection
CVSS 6.3
CVE-2025-12914 MEDIUM
aaPanel BaoTa <=11.2.x - SQL Injection
CVSS 4.7
CVE-2025-12913 MEDIUM
Code-projects Responsive Hotel Site 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12873 MEDIUM
Campcodes School File Management 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12861 MEDIUM
DedeBIZ < 6.3.2 - SQL Injection via /admin/spec_add.php flags[] Parameter
CVSS 4.7
CVE-2025-12860 MEDIUM
DedeBIZ < 6.3.2 - SQL Injection via /admin/freelist_main.php orderby Parameter
CVSS 4.7
CVE-2025-12859 MEDIUM
DedeBIZ < 6.3.2 - SQL Injection via /admin/templets_one_edit.php ids Parameter
CVSS 4.7
CVE-2025-12857 MEDIUM
Responsive Hotel Site 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12856 MEDIUM
Code-projects Responsive Hotel Site 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12855 MEDIUM
Responsive Hotel Site 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12853 MEDIUM
SourceCodester Best House Rental Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-55343 CRITICAL
Quipux 4.0.1-e1774ac - SQL Injection
CVSS 9.9
CVE-2025-12617 HIGH
itsourcecode Billing System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 4,795
Exploit Likelihood High