CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,807 vulnerabilities with CWE-74
CVE-2025-6450 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via transaction_id Parameter
CVSS 7.3
CVE-2025-6449 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via transaction_id Parameter
CVSS 7.3
CVE-2025-6448 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via /admin/delete_room.php room_id Parameter
CVSS 7.3
CVE-2025-6447 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-6446 HIGH
Client Details System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-6421 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via /admin/add_account.php name/admin_id Parameter
CVSS 7.3
CVE-2025-6420 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via room_type Parameter
CVSS 7.3
CVE-2025-6419 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via room_type Parameter
CVSS 7.3
CVE-2025-6418 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via Name Parameter in Edit Query Account
CVSS 7.3
CVE-2025-6417 MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via Award Details Parameter
CVSS 6.3
CVE-2025-6416 MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6415 MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6414 MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6413 MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6412 MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6411 MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via /admin/changepropic.php imageid Parameter
CVSS 6.3
CVE-2025-6410 MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6409 HIGH
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via Forgot Password Email Parameter
CVSS 7.3
CVE-2025-6408 HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via searchdata Parameter
CVSS 7.3
CVE-2025-6407 HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via Username Parameter in /user-login.php
CVSS 7.3
CVE-2025-6406 HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via Forgot Password Fullname Parameter
CVSS 7.3
CVE-2025-6405 HIGH
Campcodes Online Teacher Record Management System 1.0 - SQL Injection via editid Parameter
CVSS 7.3
CVE-2025-6404 HIGH
Campcodes Online Teacher Record Management System 1.0 - SQL Injection via searchdata Parameter
CVSS 7.3
CVE-2025-6403 HIGH
School Fees Payment System 1.0 - SQL Injection via /student.php ID Parameter
CVSS 7.3
CVE-2025-6394 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via firstname Parameter
CVSS 7.3
Details
Vulnerabilities 4,807
Exploit Likelihood High