CWE-74
4,990 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (4,990)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Phpgurukul 1Nipah Virus Testing Management System Jun 17, 2026 Dec 10, 2023 6.9 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file password-recovery.php. The manipulation of the argument usern...Show more |
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. |
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. |
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export. |
1Phpjabbers 1Time Slots Booking Calendar Jun 17, 2026 Dec 7, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List. |
Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails. |
Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.
|
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Dec 6, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote...Show more |
Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS...Show more |
Usedesk before 1.7.57 allows chat template injection. |
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficie...Show more |
1Fivestarplugins 1Five Star Restaurant Menu Jun 17, 2026 Nov 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable...Show more |
A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby...Show more |
2Debian Wireshark2Debian Linux WiresharkJun 17, 2026 Nov 16, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file |
HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-supplied data is not appropriately sanitiz...Show more |
1Siemens 716ag1206 2bb00 7ac2 Firmware 6ag1206 2bs00 7ac2 Firmware6ag1208 0ba00 7ac2 Firmware+68 moreJun 17, 2026 Nov 14, 2023 9.4 CRITICAL· v4 9.1 CRITICAL· v3 N/A· v2 Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. Follow-up of CVE-2022-36323. |
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some links can inject arbitrary HTML tags wh...Show more |
1Floriangaerber 1Magnesium Php Nov 21, 2024 Nov 5, 2023 N/A· v4 9.8 CRITICAL· v3 2.7 LOW· v2 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file src/Magnesium/Message/Base.php. The ma...Show more |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Nov 3, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting...Show more |
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code. |