← Back
CWE-74

4,990 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

JSON object

Loading...

CVEs (4,990)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpgurukul
1Nipah Virus Testing Management System
Jun 17, 2026
Dec 10, 2023
6.9 MEDIUM· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file password-recovery.php. The manipulation of the argument usern...Show more
A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file password-recovery.php. The manipulation of the argument username/contactno leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Phpjabbers
1Appointment Scheduler
Jun 17, 2026
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
1Phpjabbers
1Car Rental Script
Jun 17, 2026
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
1Phpjabbers
1Shuttle Booking Software
Jun 17, 2026
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.
1Phpjabbers
1Time Slots Booking Calendar
Jun 17, 2026
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
1Jorani
1Leave Management System
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.
1Mattermost
1Mattermost Server
Jun 17, 2026
Dec 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.
1Atlassian
2Confluence Data Center
Confluence Server
Jun 17, 2026
Dec 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote...Show more
This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly accessible Confluence Data Center and Server versions as listed below are at risk and require immediate attention. See the advisory for additional details Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Nov 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS...Show more
Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though.  Show less
1Usedesk
1Usedesk
Jun 17, 2026
Nov 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Usedesk before 1.7.57 allows chat template injection.
1Mainwp
1Mainwp
Jun 17, 2026
Nov 22, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficie...Show more
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficient input sanitization. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary CSS values into the site tags.Show less
1Fivestarplugins
1Five Star Restaurant Menu
Jun 17, 2026
Nov 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable...Show more
The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.Show less
1Apache
1Derby
Jun 17, 2026
Nov 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby...Show more
A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby installations, this could also allow the attacker to execute malware which was visible to and executable by the account which booted the Derby server. In LDAP-protected databases which weren't also protected by SQL GRANT/REVOKE authorization, this vulnerability could also let an attacker view and corrupt sensitive data and run sensitive database functions and procedures. Mitigation: Users should upgrade to Java 21 and Derby 10.17.1.0. Alternatively, users who wish to remain on older Java versions should build their own Derby distribution from one of the release families to which the fix was backported: 10.16, 10.15, and 10.14. Those are the releases which correspond, respectively, with Java LTS versions 17, 11, and 8. Show less
2Debian
Wireshark
2Debian Linux
Wireshark
Jun 17, 2026
Nov 16, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file
1Grocy Project
1Grocy
Jun 17, 2026
Nov 15, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-supplied data is not appropriately sanitiz...Show more
HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-supplied data is not appropriately sanitized, enabling the injection of HTML tags through parameter values. The attacker can then manipulate page content in the QR code detail popup, often coupled with social engineering tactics, exploiting both the trust of users and the application's lack of proper input handling.Show less
1Siemens
716ag1206 2bb00 7ac2 Firmware
6ag1206 2bs00 7ac2 Firmware6ag1208 0ba00 7ac2 Firmware+68 more
Jun 17, 2026
Nov 14, 2023
9.4 CRITICAL· v4
9.1 CRITICAL· v3
N/A· v2
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. Follow-up of CVE-2022-36323.
1Discourse
1Discourse
Jun 17, 2026
Nov 10, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some links can inject arbitrary HTML tags wh...Show more
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some links can inject arbitrary HTML tags when rendered through our Onebox engine. The issue is patched in version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches. There are no known workarounds.Show less
1Floriangaerber
1Magnesium Php
Nov 21, 2024
Nov 5, 2023
N/A· v4
9.8 CRITICAL· v3
2.7 LOW· v2
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file src/Magnesium/Message/Base.php. The ma...Show more
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file src/Magnesium/Message/Base.php. The manipulation of the argument email/name leads to injection. Upgrading to version 0.3.1 is able to address this issue. The patch is identified as 500d340e1f6421007413cc08a8383475221c2604. It is recommended to upgrade the affected component. VDB-244482 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.Show less
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Nov 3, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting...Show more
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Nov 1, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.