Weaknesses of type CWE-89

13,130 results

Injeção SQL

Ocorre quando entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O aplicativo executa a consulta alterada, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Example

Um formulário de login que monta a query assim: `SELECT * FROM users WHERE email = '" + emailDoFormulario + "'`. Se o usuário digitar `admin'--`, a query vira `SELECT * FROM users WHERE email = 'admin'--'` e bypassa a validação de senha, autenticando como admin.

How to mitigate

Use prepared statements ou stored procedures com parâmetros vinculados (bind parameters). Em Java use PreparedStatement; em Python use placeholders com psycopg2 ou SQLAlchemy; em qualquer linguagem evite concatenação de strings. Combine com validação de entrada e princípio do menor privilégio no banco de dados.

CVE-2023-41328MEDIUMPossibility limited SQL injection due to insufficient validation in FrappeEPSS 0.5%CVE-2025-49915CRITICALWordPress SMS Alert Order Notifications plugin <= 3.8.5 - SQL Injection vulnerabilityEPSS 0.5%CVE-2024-41550HIGHCampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_invoice_items.php?id= .EPSS 0.5%CVE-2024-5113MEDIUMCampcodes Complete Web-Based School Management System student_profile1.php sql injectionEPSS 0.5%CVE-2025-51510MEDIUMMoonShine was discovered to contain a SQL injection vulnerability under the Blog -> Categories page when using the moonshine-tree-resource (EPSS 0.5%CVE-2026-41889LOWpgx: SQL Injection via placeholder confusion with dollar quoted string literalsEPSS 0.5%CVE-2025-5210MEDIUMPHPGurukul Employee Record Management System loginerms.php sql injectionEPSS 0.5%CVE-2024-30489HIGHWordPress WP Cost Estimation & Payment Forms Builder plugin <= 10.1.75 - SQL Injection vulnerabilityEPSS 0.5%CVE-2024-33852CRITICALA SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x befoEPSS 0.5%CVE-2025-30775HIGHWordPress WPGuppy plugin <= 1.1.3 - SQL Injection vulnerabilityEPSS 0.5%CVE-2024-5112MEDIUMCampcodes Complete Web-Based School Management System student_profile.php sql injectionEPSS 0.5%CVE-2024-33853CRITICALA SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x beEPSS 0.5%CVE-2024-50823LOWA SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and passwEPSS 0.5%CVE-2024-42994HIGHVTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetaEPSS 0.5%CVE-2025-45956HIGHA SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attaEPSS 0.5%CVE-2025-8382MEDIUMCampcodes Online Hotel Reservation System edit_room.php sql injectionEPSS 0.5%CVE-2024-5115MEDIUMCampcodes Complete Web-Based School Management System teacher_profile.php sql injectionEPSS 0.5%CVE-2024-54928HIGHkashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,EPSS 0.5%CVE-2026-39111HIGHSQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the EPSS 0.5%CVE-2025-5212MEDIUMPHPGurukul Employee Record Management System editempexp.php sql injectionEPSS 0.5%