Weaknesses of type CWE-89

12,947 results

Injeção SQL

Ocorre quando entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O aplicativo executa a consulta alterada, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Example

Um formulário de login que monta a query assim: `SELECT * FROM users WHERE email = '" + emailDoFormulario + "'`. Se o usuário digitar `admin'--`, a query vira `SELECT * FROM users WHERE email = 'admin'--'` e bypassa a validação de senha, autenticando como admin.

How to mitigate

Use prepared statements ou stored procedures com parâmetros vinculados (bind parameters). Em Java use PreparedStatement; em Python use placeholders com psycopg2 ou SQLAlchemy; em qualquer linguagem evite concatenação de strings. Combine com validação de entrada e princípio do menor privilégio no banco de dados.

CVE-2024-0735MEDIUMSourceCodester Online Tours & Travels Management System expense.php exec sql injectionEPSS 0.7%CVE-2024-52335CRITICALA vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF05). The affected application do not properly sanitize inpuEPSS 0.7%CVE-2026-46624CRITICALTwenty: SQL Injection via the timeZone fieldEPSS 0.7%CVE-2024-5065MEDIUMPHPGurukul Online Course Registration System sql injectionEPSS 0.7%CVE-2023-47506HIGHWordPress Master Slider Pro Plugin <= 3.6.5 is vulnerable to SQL InjectionEPSS 0.7%CVE-2024-30867CRITICALnetentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.EPSS 0.7%CVE-2024-30865CRITICALnetentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.EPSS 0.7%CVE-2023-50718MEDIUMNocoDB SQL Injection vulnerabilityEPSS 0.7%CVE-2024-25517CRITICALRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.EPSS 0.7%CVE-2024-25519CRITICALRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.EPSS 0.7%CVE-2026-32767CRITICALSiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search APIEPSS 0.7%CVE-2023-42660HIGHMOVEit Transfer Machine Interface SQL InjectionEPSS 0.7%CVE-2024-25523CRITICALRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.EPSS 0.7%CVE-2024-0786HIGHConversios <= 7.0.7 - Authenticated (Subscriber+) SQL Injection via ee_syncProductCategoryEPSS 0.7%CVE-2023-7020MEDIUMTongda OA 2017 view.php sql injectionEPSS 0.7%CVE-2024-30985CRITICALSQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execEPSS 0.7%CVE-2023-37278MEDIUMGLPI vulnerable to SQL injection via dashboard administrationEPSS 0.7%CVE-2026-25879CRITICALLangroid has Prompt to SQL Injection, Leading to RCEEPSS 0.7%CVE-2023-7023MEDIUMTongda OA 2017 delete.php sql injectionEPSS 0.7%CVE-2023-27610MEDIUMWordPress Transbank Webpay REST Plugin <= 1.6.6 is vulnerable to SQL InjectionEPSS 0.7%