Weaknesses of type CWE-89

13,130 results

Injeção SQL

Ocorre quando entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O aplicativo executa a consulta alterada, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Example

Um formulário de login que monta a query assim: `SELECT * FROM users WHERE email = '" + emailDoFormulario + "'`. Se o usuário digitar `admin'--`, a query vira `SELECT * FROM users WHERE email = 'admin'--'` e bypassa a validação de senha, autenticando como admin.

How to mitigate

Use prepared statements ou stored procedures com parâmetros vinculados (bind parameters). Em Java use PreparedStatement; em Python use placeholders com psycopg2 ou SQLAlchemy; em qualquer linguagem evite concatenação de strings. Combine com validação de entrada e princípio do menor privilégio no banco de dados.

CVE-2025-51510MEDIUMMoonShine was discovered to contain a SQL injection vulnerability under the Blog -> Categories page when using the moonshine-tree-resource (EPSS 0.5%CVE-2025-5212MEDIUMPHPGurukul Employee Record Management System editempexp.php sql injectionEPSS 0.5%CVE-2026-4304HIGHWeePie Cookie Allow <= 3.4.11 - Unauthenticated SQL Injection via 'consent' ParameterEPSS 0.5%CVE-2024-41550HIGHCampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_invoice_items.php?id= .EPSS 0.5%CVE-2024-30535HIGHWordPress Easy Form Builder plugin <= 3.7.4 - SQL Injection vulnerabilityEPSS 0.5%CVE-2024-54928HIGHkashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,EPSS 0.5%CVE-2025-45956HIGHA SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attaEPSS 0.5%CVE-2026-41889LOWpgx: SQL Injection via placeholder confusion with dollar quoted string literalsEPSS 0.5%CVE-2024-42994HIGHVTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetaEPSS 0.5%CVE-2025-5210MEDIUMPHPGurukul Employee Record Management System loginerms.php sql injectionEPSS 0.5%CVE-2024-4992CRITICALSQL injection vulnerability in SiAdminEPSS 0.5%CVE-2025-6885MEDIUMPHPGurukul Teachers Record Management System edit-teacher-detail.php sql injectionEPSS 0.5%CVE-2025-7119MEDIUMCampcodes Complaint Management System index.php sql injectionEPSS 0.5%CVE-2024-43772CRITICALHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-8161CRITICALSQL injection vulnerability in CIGESv2 systemEPSS 0.5%CVE-2025-6828MEDIUMcode-projects Inventory Management System orders.php sql injectionEPSS 0.5%CVE-2025-6821MEDIUMcode-projects Inventory Management System createOrder.php sql injectionEPSS 0.5%CVE-2025-7193MEDIUMitsourcecode Agri-Trading Online Shopping System suppliercontroller.php sql injectionEPSS 0.5%CVE-2025-6344MEDIUMcode-projects Online Shoe Store contactus.php sql injectionEPSS 0.5%CVE-2026-33083HIGHDataEase has SQL Injection in Order By ClauseEPSS 0.5%