Fallos del tipo CWE-89

13.087 resultados

Injeção de SQL

Ocorre quando dados fornecidos por um usuário são incorporados diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante modifique a lógica da consulta. O risco é grave: exposição de dados sensíveis, modificação ou deleção de registros, e até comprometimento do servidor de banco de dados.

Ejemplo

Um formulário de login que constrói a consulta como `SELECT * FROM users WHERE login = '` + entrada_do_usuario + `'` permite que alguém digite `admin' --` e contorne a verificação de senha, ou `' OR '1'='1` para listar todos os usuários.

Cómo mitigar

Use prepared statements ou stored procedures com parâmetros vinculados (nunca concatenação de strings). Se necessário filtrar, aplique whitelist rigorosa e escape adequado para o banco de dados específico. Implemente validação de entrada e princípio do menor privilégio na conta do banco.

CVE-2026-28805HIGHOpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` ParameterEPSS 0.5%CVE-2026-45288CRITICALMarten has an SQL injection vulnerability in its full-text search regConfig parameterEPSS 0.5%CVE-2024-1839CRITICALIntrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticaEPSS 0.5%CVE-2026-69240CRITICALSequelize: SQL Injection (Oracle DB)EPSS 0.5%CVE-2022-3013MEDIUMSourceCodester Simple Task Managing System loginVaLidation.php sql injectionEPSS 0.5%CVE-2024-6274MEDIUMlahirudanushka School Management System Attendance Report Page attendancelist.php sql injectionEPSS 0.5%CVE-2025-69948CRITICALSourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.EPSS 0.5%CVE-2023-47236HIGHWordPress iPages Flipbook Plugin <= 1.4.8 is vulnerable to SQL InjectionEPSS 0.5%CVE-2024-43699CRITICALDelta Electronics DIAEnergie SQL InjectionEPSS 0.5%CVE-2025-0173MEDIUMSourceCodester Online Eyewear Shop view_order.php sql injectionEPSS 0.5%CVE-2026-27697MEDIUMbaserCMS: SQL injection vulnerability in blog postEPSS 0.5%CVE-2025-25775CRITICALCodeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.EPSS 0.5%CVE-2025-31553CRITICALWordPress Advanced WooCommerce Product Sales Reporting plugin <= 4.1.1 - SQL Injection vulnerabilityEPSS 0.5%CVE-2026-9711CRITICALEventON - WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated Blind SQL Injection via Search ParameterEPSS 0.5%CVE-2026-3287MEDIUMyoulaitech youlai-mall App-side Product Pagination Endpoint SpuController.java listPagedSpuForApp sql injectionEPSS 0.5%CVE-2024-37840HIGHSQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remotEPSS 0.5%CVE-2024-5589MEDIUMNetentsec NS-ASG Application Security Gateway sql injectionEPSS 0.5%CVE-2023-52201HIGHWordPress pTypeConverter Plugin <= 0.2.8.1 is vulnerable to SQL InjectionEPSS 0.5%CVE-2023-52142HIGHWordPress Events Shortcodes & Templates For The Events Calendar Plugin <= 2.3.1 is vulnerable to SQL InjectionEPSS 0.5%CVE-2024-11213MEDIUMSourceCodester Best Employee Management System edit_role.php sql injectionEPSS 0.5%