Weaknesses of type CWE-74
4,802 resultsInjeção de código
É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.
Example
Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.
How to mitigate
Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.
CVE-2025-7479MEDIUMPHPGurukul Vehicle Parking Management System view--detail.php sql injectionEPSS 0.4%CVE-2025-7166MEDIUMcode-projects Responsive Blog Site single.php sql injectionEPSS 0.4%CVE-2023-35075LOWHTML injection via channel autocompleteEPSS 0.4%CVE-2026-13529MEDIUMYzmCMS index.php sql injectionEPSS 0.4%CVE-2026-0590MEDIUMcode-projects Online Product Reservation System POST Parameter delete.php sql injectionEPSS 0.4%CVE-2025-15212MEDIUMcode-projects Refugee Food Management System regfood.php sql injectionEPSS 0.4%CVE-2026-0584MEDIUMcode-projects Online Product Reservation System left_cart.php sql injectionEPSS 0.4%CVE-2026-0591MEDIUMcode-projects Online Product Reservation System Cart Update update.php sql injectionEPSS 0.4%CVE-2025-13303MEDIUMcode-projects Courier Management System search-edit.php sql injectionEPSS 0.4%CVE-2025-13168MEDIUMury-erp ury pos_extend.py overrided_past_order_list sql injectionEPSS 0.4%CVE-2025-15209MEDIUMcode-projects Refugee Food Management System editfood.php sql injectionEPSS 0.4%CVE-2025-15211MEDIUMcode-projects Refugee Food Management System refugee.php sql injectionEPSS 0.4%CVE-2025-15210MEDIUMcode-projects Refugee Food Management System editrefugee.php sql injectionEPSS 0.4%CVE-2026-16747MEDIUMKirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email ActionsEPSS 0.4%CVE-2025-13267MEDIUMSourceCodester Dental Clinic Appointment Reservation System success.php sql injectionEPSS 0.4%CVE-2025-2625MEDIUMwestboy CicadasCMS page sql injectionEPSS 0.4%CVE-2025-5697MEDIUMBrilliance Golden Link Secondary System tcCustDeferPosiQuery.htm sql injectionEPSS 0.4%CVE-2025-12610MEDIUMCodeAstro Gym Management System view-progress-report.php sql injectionEPSS 0.4%CVE-2025-32390HIGHEspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeoverEPSS 0.4%CVE-2025-5696MEDIUMBrilliance Golden Link Secondary System rentChangeCheckInfoPage.htm sql injectionEPSS 0.4%