Fallos del tipo CWE-89

13.084 resultados

Injeção de SQL

Ocorre quando dados fornecidos por um usuário são incorporados diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante modifique a lógica da consulta. O risco é grave: exposição de dados sensíveis, modificação ou deleção de registros, e até comprometimento do servidor de banco de dados.

Ejemplo

Um formulário de login que constrói a consulta como `SELECT * FROM users WHERE login = '` + entrada_do_usuario + `'` permite que alguém digite `admin' --` e contorne a verificação de senha, ou `' OR '1'='1` para listar todos os usuários.

Cómo mitigar

Use prepared statements ou stored procedures com parâmetros vinculados (nunca concatenação de strings). Se necessário filtrar, aplique whitelist rigorosa e escape adequado para o banco de dados específico. Implemente validação de entrada e princípio do menor privilégio na conta do banco.

CVE-2024-37090HIGHSQL Injection vulnerability in multiple StylemixThemes premium themesEPSS 0.5%CVE-2026-63233CRITICALSQL injection and unsafe deserialisation vulnerabilityEPSS 0.5%CVE-2023-51547HIGHWordPress Fluent Support Plugin <= 1.7.6 is vulnerable to SQL InjectionEPSS 0.5%CVE-2023-50851HIGHWordPress Simply Schedule Appointments Plugin < 1.6.6.1 is vulnerable to SQL InjectionEPSS 0.5%CVE-2025-30886CRITICALWordPress JS Help Desk plugin <= 2.9.2 - SQL Injection vulnerabilityEPSS 0.5%CVE-2026-73670HIGHCMS Admin SQL Injection via db_data.php table_name ParameterEPSS 0.5%CVE-2023-50852HIGHWordPress BookIt Plugin <= 2.4.3 is vulnerable to SQL InjectionEPSS 0.5%CVE-2025-1768MEDIUMSEO Plugin by Squirrly SEO <= 12.4.05 - Authenticated (Subscriber+) SQL Injection via search ParameterEPSS 0.5%CVE-2026-63232CRITICALSQL injection and unsafe deserialisation vulnerabilityEPSS 0.5%CVE-2023-50855HIGHWordPress Pre* Party Resource Hints Plugin <= 1.8.18 is vulnerable to SQL InjectionEPSS 0.5%CVE-2023-50857HIGHWordPress Automation By Autonami Plugin <= 2.6.1 is vulnerable to SQL InjectionEPSS 0.5%CVE-2023-50849HIGHWordPress e2pdf Plugin <= 1.20.23 is vulnerable to SQL InjectionEPSS 0.5%CVE-2023-53734HIGHdawa-pharma-1.0 - SQL Injection via Email ParameterEPSS 0.5%CVE-2026-63234CRITICALSQL injection and unsafe deserialisation vulnerabilityEPSS 0.5%CVE-2023-50843HIGHWordPress Clockwork SMS Notfications Plugin <= 3.0.4 is vulnerable to SQL InjectionEPSS 0.5%CVE-2024-8150MEDIUMContiNew Admin user sql injectionEPSS 0.5%CVE-2024-33546CRITICALWordPress WZone plugin <= 14.0.10 - Arbitrary SQL Update Execution vulnerabilityEPSS 0.5%CVE-2024-42552HIGHHotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_histoEPSS 0.5%CVE-2026-44447HIGHERPNext: Possibility of SQL Injection due to missing validationEPSS 0.5%CVE-2023-50847HIGHWordPress Welcart e-Commerce Plugin <= 2.9.3 is vulnerable to SQL InjectionEPSS 0.5%