Injection (CWE-74)
CWE-74 is the broad Class for injection. The product builds a command, data structure or record from outside input and does not neutralize special elements that change how a downstream component parses it. MITRE discourages mapping vulnerabilities to CWE-74 because it is high-level and more specific children usually fit better.
About CWE-74
Consequences listed by MITRE include disclosure of application data, bypass of authentication, altered execution logic, loss of data integrity and unlogged activity.
MITRE marks CWE-74 as DISCOURAGED for mapping real-world vulnerabilities because it is high-level and often misused; examine its children for a better fit.
Mitigations
- +Choose programming languages and supporting technologies that are not subject to these parsing issues.
- +Combine allowlist and denylist parsing to filter control-plane syntax out of all input.
- +Map each finding to a more specific child entry such as SQL injection or OS command injection, which carry targeted mitigations.
Detection
Automated static analysis (SAST) is rated highly effective, using data flow and control flow models to connect input sources with sinks.
CWE-74 Vulnerabilities
56 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) | Hitachi Vantara | 8.8 | 97.7% | KEV | 2023-04-03 |
| CVE-2022-46169 | Unauthenticated Command Injection | Cacti | 9.8 | 99.8% | KEV | 2022-12-05 |
| CVE-2026-22200 | osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read | Enhancesoft | 8.7 | 73.6% | 2026-01-12 | |
| CVE-2026-2537 | Comfast CF-E4 HTTP POST Request mbox-config command injection | Comfast | 5.8 | 25.8% | 2026-02-16 | |
| CVE-2026-4197 | D-Link DNS-1550-04 download_mgr.cgi RSS_Item_List command injection | D-Link | 6.5 | 23.7% | 2026-03-15 | |
| CVE-2026-2000 | DCN DCME-320 Web Management Backend bridge_cfg.php apply_config command injection | DCN | 5.8 | 19.7% | 2026-02-06 | |
| CVE-2026-1419 | D-Link DCS700l Web Form setDayNightMode command injection | D-Link | 5.8 | 17.2% | 2026-01-26 | |
| CVE-2026-1125 | D-Link DIR-823X set_wifidog_settings sub_412E7C command injection | D-Link | 7.5 | 15.7% | 2026-01-18 | |
| CVE-2026-2535 | Comfast CF-N1 V2 mbox-config sub_44AB9C command injection | Comfast | 6.5 | 14.3% | 2026-02-16 | |
| CVE-2026-2534 | Comfast CF-N1 V2 mbox-config sub_44AC4C command injection | Comfast | 6.5 | 13.8% | 2026-02-16 | |
| CVE-2026-0732 | D-Link DI-8200G upgrade_filter.asp command injection | D-Link | 6.5 | 11.7% | 2026-01-08 | |
| CVE-2026-2823 | Comfast CF-E7 webmggnt mbox-config sub_41ACCC command injection | Comfast | 6.5 | 11.5% | 2026-02-20 | |
| CVE-2026-2824 | Comfast CF-E7 webmggnt mbox-config sub_441CF4 command injection | Comfast | 6.5 | 11.5% | 2026-02-20 | |
| CVE-2026-3661 | Wavlink WL-NU516U1 adm.cgi ota_new_upgrade command injection | Wavlink | 5.8 | 11.3% | 2026-03-07 | |
| CVE-2026-3662 | Wavlink WL-NU516U1 adm.cgi usb_p910 command injection | Wavlink | 5.8 | 11.3% | 2026-03-07 | |
| CVE-2026-3798 | Comfast CF-AC100 Request Path mbox-config sub_44AC14 command injection | Comfast | 5.8 | 11.3% | 2026-03-09 | |
| CVE-2026-2080 | UTT HiPER 810 formUser setSysAdm command injection | UTT | 8.6 | 10.8% | 2026-02-07 | |
| CVE-2026-3612 | Wavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection | Wavlink | 8.6 | 10.4% | 2026-03-06 | |
| CVE-2026-5339 | Tenda G103 Setting gpon.lua action_set_net_settings command injection | Tenda | 5.8 | 10.2% | 2026-04-02 | |
| CVE-2026-2182 | UTT 进取 521G setSysAdm doSystem command injection | UTT | 8.6 | 9.7% | 2026-02-08 | |
| CVE-2026-0581 | Tenda AC1206 httpd BehaviorManager formBehaviorManager command injection | Tenda | 6.5 | 9.4% | 2026-01-05 | |
| CVE-2026-4228 | LB-LINK BL-WR9000 set_wifi sub_458754 command injection | LB-LINK | 6.5 | 8.9% | 2026-03-16 | |
| CVE-2026-5183 | TRENDnet TEW-713RE addRouting sub_421494 command injection | TRENDnet | 6.5 | 8.9% | 2026-03-31 | |
| CVE-2026-2956 | qinming99 dst-admin restore revertBackup command injection | qinming99 | 6.5 | 8.8% | 2026-02-22 | |
| CVE-2026-2527 | Wavlink WL-WN579A3 login.cgi command injection | Wavlink | 6.5 | 8.7% | 2026-02-16 | |
| CVE-2026-3064 | HummerRisk Cloud Task Scheduler ResourceCreateService.java command injection | - | 6.5 | 8.6% | 2026-02-24 | |
| CVE-2026-3065 | HummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult command injection | - | 6.5 | 8.6% | 2026-02-24 | |
| CVE-2026-3066 | HummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection | - | 6.5 | 8.6% | 2026-02-24 | |
| CVE-2026-5184 | TRENDnet TEW-713RE setSysAdm command injection | TRENDnet | 6.5 | 8.5% | 2026-03-31 | |
| CVE-2026-2528 | Wavlink WL-WN579A3 wireless.cgi Delete_Mac_list command injection | Wavlink | 6.5 | 8.4% | 2026-02-16 | |
| CVE-2026-2526 | Wavlink WL-WN579A3 wireless.cgi multi_ssid command injection | Wavlink | 6.5 | 8.4% | 2026-02-16 | |
| CVE-2026-2530 | Wavlink WL-WN579A3 wireless.cgi AddMac command injection | Wavlink | 6.5 | 8.4% | 2026-02-16 | |
| CVE-2026-5338 | Tenda G103 Setting system.lua action_set_system_settings command injection | Tenda | 5.8 | 8.3% | 2026-04-02 | |
| CVE-2026-2615 | Wavlink WL-NU516U1 firewall.cgi singlePortForwardDelete command injection | Wavlink | 8.6 | 8.0% | 2026-02-17 | |
| CVE-2026-1192 | Tosei Online Store Management System ネット店舗管理システム imode_alldata.php command injection | Tosei | 7.5 | 6.9% | 2026-01-19 | |
| CVE-2026-2227 | D-Link DCS-931L setSystemAdmin doSystem command injection | D-Link | 5.8 | 6.8% | 2026-02-09 | |
| CVE-2026-2163 | D-Link DIR-600 ssdp.cgi command injection | D-Link | 5.8 | 6.6% | 2026-02-08 | |
| CVE-2026-4554 | Tenda F453 WriteFacMac FormWriteFacMac privilege escalation | Tenda | 6.5 | 6.5% | 2026-03-22 | |
| CVE-2026-5153 | Tenda CH22 WriteFacMac FormWriteFacMac command injection | Tenda | 6.5 | 6.5% | 2026-03-30 | |
| CVE-2026-7102 | Tenda F456 httpd WriteFacMac FromWriteFacMac command injection | Tenda | 6.5 | 6.5% | 2026-04-27 | |
| CVE-2026-6989 | Tenda F453 Telnet Service telnet TendaTelnet command injection | Tenda | 6.5 | 6.3% | 2026-04-25 | |
| CVE-2026-4203 | D-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection | D-Link | 6.5 | 6.1% | 2026-03-16 | |
| CVE-2026-7690 | Wavlink WL-WN570HA1 adm.cgi set_sys_adm command injection | Wavlink | 6.5 | 6.0% | 2026-05-03 | |
| CVE-2026-4209 | D-Link DNS-1550-04 account_mgr.cgi cgi_chg_admin_pw command injection | D-Link | 6.5 | 5.8% | 2026-03-16 | |
| CVE-2026-4196 | D-Link DNS-1550-04 remote_backup.cgi cgi_set_rsync_server command injection | D-Link | 6.5 | 5.8% | 2026-03-15 | |
| CVE-2026-4207 | D-Link DNS-1550-04 system_mgr.cgi cgi_ntp_time command injection | D-Link | 6.5 | 5.8% | 2026-03-16 | |
| CVE-2026-1066 | kalcaddle kodbox Compression zip command injection | kalcaddle | 6.5 | 5.6% | 2026-01-17 | |
| CVE-2026-3704 | Wavlink NU516U1 Incomplete Fix CVE-2025-10959 firewall.cgi sub_405B2C command injection | Wavlink | 5.8 | 5.5% | 2026-03-08 | |
| CVE-2026-4195 | D-Link DNS-1550-04 wizard_mgr.cgi command injection | D-Link | 6.5 | 5.5% | 2026-03-15 | |
| CVE-2026-4204 | D-Link DNS-1550-04 gui_mgr.cgi cgi_mycloud_auto_downlaod command injection | D-Link | 6.5 | 5.5% | 2026-03-16 | |
| CVE-2026-4210 | D-Link DNS-1550-04 time_machine.cgi cgi_tm_set_share command injection | D-Link | 6.5 | 5.5% | 2026-03-16 | |
| CVE-2026-2085 | D-Link DWR-M921 USSD Configuration Endpoint formUSSDSetup sub_419F20 command injection | D-Link | 8.6 | 5.2% | 2026-02-07 | |
| CVE-2026-4205 | D-Link DNS-1550-04 app_mgr.cgi FTP_Server_BlockIP_Del command injection | D-Link | 6.5 | 5.1% | 2026-03-16 | |
| CVE-2026-4206 | D-Link DNS-1550-04 dsk_mgr.cgi ScanDisk_run_e2fsck command injection | D-Link | 6.5 | 5.1% | 2026-03-16 | |
| CVE-2026-10060 | TRENDnet TEW-432BRP formSetRoute command injection | TRENDnet | 6.5 | 5.0% | 2026-05-29 | |
| CVE-2026-10061 | TRENDnet TEW-432BRP formWPS command injection | TRENDnet | 6.5 | 5.0% | 2026-05-29 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What does CWE-74 cover?→
CWE-74 is the parent Class for injection weaknesses, where outside input changes how a downstream component interprets output. SQL injection, OS command injection and cross-site scripting sit beneath it.
Can CWE-74 be used to classify a CVE?→
MITRE marks CWE-74 as discouraged for vulnerability mapping because of its high abstraction and frequent misuse. Its children and descendants are the recommended targets.
How many exploited vulnerabilities are classified as CWE-74?→
This database lists 56 CVE records mapped to CWE-74 by their CVE Numbering Authority. 2 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2022-43769, CVE-2022-46169, CVE-2026-22200.
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.