A05:2025 Injection
Untrusted input crosses an interpreter boundary without proper neutralization. SQL, OS command, LDAP, XSS, template injection.
Related on the LLM side: OWASP Top 10 for LLMs LLM01:2025.
Member CWEs (37)
- CWE-20 Improper Input Validation
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-76 Improper Neutralization of Equivalent Special Elements
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
- CWE-83 Improper Neutralization of Script in Attributes in a Web Page
- CWE-86 Improper Neutralization of Invalid Characters in Identifiers in Web Pages
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
- CWE-91 XML Injection (aka Blind XPath Injection)
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
- CWE-94 Improper Control of Generation of Code ('Code Injection')
- CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
- CWE-96 Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
- CWE-97 Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
- CWE-99 Improper Control of Resource Identifiers ('Resource Injection')
- CWE-103 Struts: Incomplete validate() Method Definition
- CWE-104 Struts: Form Bean Does Not Extend Validation Class
- CWE-112 Missing XML Validation
- CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
- CWE-114 Process Control
- CWE-115 Misinterpretation of Input
- CWE-116 Improper Encoding or Escaping of Output
- CWE-129 Improper Validation of Array Index
- CWE-159 Improper Handling of Invalid Use of Special Elements
- CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
- CWE-493 Critical Public Variable Without Final Modifier
- CWE-500 Public Static Field Not Marked Final
- CWE-564 SQL Injection: Hibernate
- CWE-610 Externally Controlled Reference to a Resource in Another Sphere
- CWE-643 Improper Neutralization of Data within XPath Expressions ('XPath Injection')
- CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax
- CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
Mapped NIST 800-53 r5 controls (1)
Our two-way, human-QA’d reading of how this category and each NIST 800-53 control relate. No external body publishes an OWASP→800-53 mapping, so these are our assessment.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Tagged CVEs (showing 50 most recent of 99,305)
- CVE-2026-77992
- CVE-2026-77988
- CVE-2026-77945
- CVE-2026-77811
- CVE-2026-77810
- CVE-2026-77806
- CVE-2026-77710
- CVE-2026-77683
- CVE-2026-77647
- CVE-2026-77645
- CVE-2026-77643
- CVE-2026-77506
- CVE-2026-77415
- CVE-2026-77414
- CVE-2026-77413
- CVE-2026-77392
- CVE-2026-77084
- CVE-2026-77080
- CVE-2026-77077
- CVE-2026-77075
- CVE-2026-77074
- CVE-2026-77072
- CVE-2026-77071
- CVE-2026-77031
- CVE-2026-77028
- CVE-2026-77027
- CVE-2026-77025
- CVE-2026-77020
- CVE-2026-77019
- CVE-2026-77004
- CVE-2026-76998
- CVE-2026-76997
- CVE-2026-76996
- CVE-2026-76993
- CVE-2026-76991
- CVE-2026-76990
- CVE-2026-76904
- CVE-2026-76833
- CVE-2026-76785
- CVE-2026-76783
- CVE-2026-76764
- CVE-2026-76762
- CVE-2026-76761
- CVE-2026-76760
- CVE-2026-76635
- CVE-2026-76613
- CVE-2026-76612
- CVE-2026-76605
- CVE-2026-76604
- CVE-2026-76602
Data: OWASP Top 10:2025 (CC BY-SA 4.0) · CWE memberships from cwe-api.mitre.org (meta-category CWE-1440).