Weaknesses of type CWE-89

12,989 results

Injeção SQL

Ocorre quando entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O aplicativo executa a consulta alterada, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Example

Um formulário de login que monta a query assim: `SELECT * FROM users WHERE email = '" + emailDoFormulario + "'`. Se o usuário digitar `admin'--`, a query vira `SELECT * FROM users WHERE email = 'admin'--'` e bypassa a validação de senha, autenticando como admin.

How to mitigate

Use prepared statements ou stored procedures com parâmetros vinculados (bind parameters). Em Java use PreparedStatement; em Python use placeholders com psycopg2 ou SQLAlchemy; em qualquer linguagem evite concatenação de strings. Combine com validação de entrada e princípio do menor privilégio no banco de dados.

CVE-2024-10988MEDIUMcode-projects E-Health Care System doctor_login.php sql injectionEPSS 0.6%CVE-2016-20097HIGHWeaver E-cology 8.0 SQL Injection File Read via SignatureDownLoadEPSS 0.6%CVE-2023-6659MEDIUMCampcodes Web-Based Student Clearance System login.php sql injectionEPSS 0.6%CVE-2024-57615HIGHAn issue in the BATcalcbetween_intern component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted EPSS 0.6%CVE-2025-8773MEDIUMDinstar Monitoring Platform 甘肃省危险品库监控平台 login_getPasswordErrorNum.action sql injectionEPSS 0.6%CVE-2024-57616HIGHAn issue in the vscanf component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.EPSS 0.6%CVE-2023-5681MEDIUMNetentsec NS-ASG Application Security Gateway list_addr_fwresource_ip.php sql injectionEPSS 0.6%CVE-2023-6276MEDIUMTongda OA 2017 delete.php sql injectionEPSS 0.6%CVE-2025-57529CRITICALYouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input EPSS 0.6%CVE-2024-30238HIGHWordPress Photos and Files Contest Gallery plugin <= 21.3.2 - SQL Injection vulnerabilityEPSS 0.6%CVE-2024-7221MEDIUMSourceCodester/Campcodes School Log Management System manage_user.php sql injectionEPSS 0.6%CVE-2024-42885CRITICALSQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jspEPSS 0.6%CVE-2024-2527MEDIUMMAGESH-K21 Online-College-Event-Hall-Reservation-System rooms.php sql injectionEPSS 0.6%CVE-2022-45205MEDIUMJeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.EPSS 0.6%CVE-2024-10687CRITICALPhotos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL InjectionEPSS 0.6%CVE-2025-4250MEDIUMcode-projects Nero Social Networking Site index.php sql injectionEPSS 0.6%CVE-2024-30236HIGHWordPress Contest Gallery plugin <= 21.3.4 - SQL Injection vulnerabilityEPSS 0.6%CVE-2025-1133CRITICALSQL Injection in ChurchCRM EID Parameter via EditEventAttendees.phpEPSS 0.6%CVE-2025-4241MEDIUMPHPGurukul Teacher Subject Allocation Management System search.php sql injectionEPSS 0.6%CVE-2025-4226MEDIUMPHPGurukul/Campcodes Cyber Cafe Management System add-computer.php sql injectionEPSS 0.6%