Weaknesses of type CWE-89

12,881 results

Injeção SQL

Ocorre quando entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O aplicativo executa a consulta alterada, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Example

Um formulário de login que monta a query assim: `SELECT * FROM users WHERE email = '" + emailDoFormulario + "'`. Se o usuário digitar `admin'--`, a query vira `SELECT * FROM users WHERE email = 'admin'--'` e bypassa a validação de senha, autenticando como admin.

How to mitigate

Use prepared statements ou stored procedures com parâmetros vinculados (bind parameters). Em Java use PreparedStatement; em Python use placeholders com psycopg2 ou SQLAlchemy; em qualquer linguagem evite concatenação de strings. Combine com validação de entrada e princípio do menor privilégio no banco de dados.

CVE-2022-43352HIGHSanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.EPSS 0.9%CVE-2022-41551HIGHGarage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php.EPSS 0.9%CVE-2022-43355HIGHSanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.EPSS 0.9%CVE-2023-26093CRITICALLiima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.EPSS 0.9%CVE-2024-50717CRITICALSQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the client parameter in the /recupEPSS 0.9%CVE-2023-4740MEDIUMIBOS OA Delete Draft delDraft&archiveId=0 sql injectionEPSS 0.9%CVE-2024-50716CRITICALSQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the id parameter in the /sendPushMEPSS 0.9%CVE-2022-43022MEDIUMOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.EPSS 0.9%CVE-2022-43021MEDIUMOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.EPSS 0.9%CVE-2022-43023MEDIUMOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.EPSS 0.9%CVE-2022-43020MEDIUMOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.EPSS 0.9%CVE-2023-48863HIGHSEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existinEPSS 0.9%CVE-2023-22727CRITICALDatabase Query::offset() and limit() vulnerable to SQL injection in cakephpEPSS 0.9%CVE-2022-41731HIGHIBM Watson Knowledge Catalog on Cloud Pak SQL injectionEPSS 0.9%CVE-2024-30241HIGHWordPress ProfileGrid – User Profiles, Memberships, Groups and Communities plugin <= 5.7.1 - Contributor+ SQL Injection vulnerabilityEPSS 0.9%CVE-2015-10034MEDIUMj-nowak workout-organizer sql injectionEPSS 0.9%CVE-2020-13590MEDIUMMultiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A spEPSS 0.9%CVE-2023-6652HIGHcode-projects Matrimonial Site register.php register sql injectionEPSS 0.9%CVE-2025-63689CRITICALMultiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) alloEPSS 0.9%CVE-2023-6651HIGHcode-projects Matrimonial Site sql injectionEPSS 0.9%