Weaknesses of type CWE-74
4,755 resultsInjeção de código
É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.
Example
Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.
How to mitigate
Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.
CVE-2025-3045MEDIUMoretnom23/SourceCodester Apartment Visitor Management System remove-apartment.php sql injectionEPSS 0.6%CVE-2025-3118MEDIUMSourceCodester Online Tutor Portal view_course.php sql injectionEPSS 0.6%CVE-2025-2112MEDIUMuser-xiangpeng yaoqishan MediaInfoService.java getMediaLisByFilter sql injectionEPSS 0.6%CVE-2025-3140MEDIUMSourceCodester Online Medicine Ordering System view_category.php sql injectionEPSS 0.6%CVE-2025-3209MEDIUMcode-projects Patient Record Management System add_patient.php sql injectionEPSS 0.6%CVE-2025-9692MEDIUMCampcodes Online Shopping System product.php sql injectionEPSS 0.6%CVE-2025-1576MEDIUMcode-projects Real Estate Property Management System ajax_state.php sql injectionEPSS 0.6%CVE-2025-22978CRITICALeladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.EPSS 0.6%CVE-2024-12789MEDIUMPbootCMS IndexController.php code injectionEPSS 0.6%CVE-2025-4026MEDIUMPHPGurukul Nipah Virus Testing Management System profile.php sql injectionEPSS 0.6%CVE-2025-13786MEDIUMtaosir WTCMS index.php fetch code injectionEPSS 0.6%CVE-2025-3310MEDIUMcode-projects Blood Bank Management System delete.php sql injectionEPSS 0.6%CVE-2025-3316MEDIUMPHPGurukul Men Salon Management System search-invoices.php sql injectionEPSS 0.6%CVE-2025-4034MEDIUMprojectworlds Online Examination System inser_doc_process.php sql injectionEPSS 0.6%CVE-2025-3309MEDIUMcode-projects Blood Bank Management System campsdetails.php sql injectionEPSS 0.6%CVE-2025-0168MEDIUMcode-projects Job Recruitment _feedback_system.php sql injectionEPSS 0.6%CVE-2025-3314MEDIUMSourceCodester Apartment Visitor Management System forgotpw.php sql injectionEPSS 0.6%CVE-2025-3998MEDIUMCodeAstro Membership Management System renew.php sql injectionEPSS 0.6%CVE-2025-3339MEDIUMcodeprojects Online Restaurant Management System user_update.php sql injectionEPSS 0.6%CVE-2025-4024MEDIUMitsourcecode Placement Management System add_drive.php sql injectionEPSS 0.6%