CWE-99: Resource Injection
The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.
59 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-2410 — Admin Authorized Port (iptables) manipulation (open/close/disable ports)
- CVE-2025-0756 — Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')
- CVE-2024-57971 — DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:
- CVE-2024-5706 — Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')
- CVE-2026-3693 — Shy2593666979 AgentChat User Endpoint user.py update_user_info resource injection
- CVE-2025-43491 — Poly Lens Desktop Application – Privilege Escalation
- CVE-2026-5414 — Newgen OmniDocs WebApiRequestRedirection resource injection
- CVE-2025-9619 — E4 Sistemas Mercatus ERP id resource injection
- CVE-2025-1645 — Benner Connecta EditarLogado resource injection
- CVE-2024-4817 — Campcodes Online Laundry Management System HTTP Request Parameter manage_user.php resource injection
- CVE-2024-4294 — PHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injection
- CVE-2026-81521 — Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver
- CVE-2026-33603 — Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This
- CVE-2025-9264 — Xuxueli xxl-job Jobs JobInfoController.java remove resource injection
- CVE-2026-5031 — BichitroGan ISP Billing Software Endpoint users-view resource injection
- CVE-2025-9263 — Xuxueli xxl-job JobLogController.java getJobsByGroup resource injection
- CVE-2025-8793 — LitmusChaos Litmus resource injection
- CVE-2025-3855 — CodeCanyon RISE Ultimate Project Manager Profile Picture save_profile_image resource injection
- CVE-2025-3405 — FCJ Venture Builder appclientefiel HTTP GET Request ObterPedido resource injection
- CVE-2025-2125 — Control iD RH iD PDF Document companyId resource injection
Recently published
- CVE-2026-81524 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver
- CVE-2026-81521 — Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver
- CVE-2026-15186 — macrozheng mall Portal Endpoint create resource injection
- CVE-2026-13493 — AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection
- CVE-2026-12207 — medkey-org medkey HTTP REST API PatientController.php actionGetPatientById resource injection
- CVE-2026-10624 — SourceCodester Human Resource Management Employee View detailview.php resource injection
- CVE-2026-10299 — code-projects Online Hospital Management System viewdoctortimings.php resource injection
- CVE-2026-10168 — OUSL-GROUP-BrinaryBrains School Student Management System Parents.php marks resource injection
- CVE-2026-9438 — yashpokharna2555 StudentManagementSystem courseDel.php resource injection
- CVE-2026-33603 — Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This
- CVE-2026-7303 — Xuxueli xxl-job Execution Log JobLogController.java logDetailCat resource injection
- CVE-2026-5414 — Newgen OmniDocs WebApiRequestRedirection resource injection
- CVE-2026-5031 — BichitroGan ISP Billing Software Endpoint users-view resource injection
- CVE-2026-3693 — Shy2593666979 AgentChat User Endpoint user.py update_user_info resource injection
- CVE-2025-12918 — yungifez Skuul School Management System View Fee Invoice fee-invoices resource injection
- CVE-2025-12270 — LearnHouse Student Assignment Submission sub_file resource injection
- CVE-2025-43491 — Poly Lens Desktop Application – Privilege Escalation
- CVE-2025-9619 — E4 Sistemas Mercatus ERP id resource injection
- CVE-2025-9264 — Xuxueli xxl-job Jobs JobInfoController.java remove resource injection
- CVE-2025-9263 — Xuxueli xxl-job JobLogController.java getJobsByGroup resource injection