Weaknesses of type CWE-74
4,799 resultsInjeção de código
É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.
Example
Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.
How to mitigate
Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.
CVE-2025-14968MEDIUMcode-projects Simple Stock System update.php sql injectionEPSS 0.4%CVE-2025-13585MEDIUMitsourcecode COVID Tracking System login.php sql injectionEPSS 0.4%CVE-2025-14210MEDIUMprojectworlds Advanced Library Management System delete_member.php sql injectionEPSS 0.4%CVE-2026-0565MEDIUMcode-projects Content Management System delete.php sql injectionEPSS 0.4%CVE-2025-14666MEDIUMitsourcecode COVID Tracking System page sql injectionEPSS 0.4%CVE-2025-14209MEDIUMCampcodes School File Management System update_query.php sql injectionEPSS 0.4%CVE-2025-14649MEDIUMitsourcecode Online Cake Ordering System supplier.php sql injectionEPSS 0.4%CVE-2025-15186MEDIUMcode-projects Refugee Food Management System addusers.php sql injectionEPSS 0.4%CVE-2025-15034MEDIUMitsourcecode Student Management System record.php sql injectionEPSS 0.4%CVE-2025-14249MEDIUMcode-projects Online Ordering System user_school.php sql injectionEPSS 0.4%CVE-2025-14652MEDIUMitsourcecode Online Cake Ordering System admindetail.php sql injectionEPSS 0.4%CVE-2025-14950MEDIUMcode-projects Scholars Tracking System delete_post.php sql injectionEPSS 0.4%CVE-2025-14637MEDIUMitsourcecode Online Pet Shop Management System addcnp.php sql injectionEPSS 0.4%CVE-2026-0569MEDIUMcode-projects Online Music Site AlbumByCategory.php sql injectionEPSS 0.4%CVE-2025-13272MEDIUMCampcodes School Fees Payment Management System manage_course.php sql injectionEPSS 0.4%CVE-2025-13557MEDIUMCampcodes Online Polling System registeracc.php sql injectionEPSS 0.4%CVE-2025-15181MEDIUMcode-projects Refugee Food Management System pagenateRefugeesList.php sql injectionEPSS 0.4%CVE-2025-14215MEDIUMcode-projects Currency Exchange System edit.php sql injectionEPSS 0.4%CVE-2025-14258MEDIUMitsourcecode Student Management System newsubject.php sql injectionEPSS 0.4%CVE-2025-14638MEDIUMitsourcecode Online Pet Shop Management System update_cnp.php sql injectionEPSS 0.4%