Falhas do tipo CWE-74

4.802 resultados

Injeção de código

Ocorre quando dados não confiáveis (entrada do usuário) são incorporados diretamente em comandos ou consultas executadas pelo sistema, sem validação ou escape. Um atacante consegue injetar código malicioso (SQL, script, comando) que será interpretado e executado com os privilégios da aplicação.

Exemplo

Uma busca por usuário que concatena a entrada diretamente em SQL: `SELECT * FROM users WHERE name = '` + input + `'`. Se o usuário digitar `' OR '1'='1`, a consulta retorna todos os registros. Com entrada maliciosa como `'; DROP TABLE users; --`, o banco é destruído.

Como mitigar

Use prepared statements ou queries parametrizadas (placeholders) para separar dados de código. Valide e sanitize todas as entradas, aplicando listas de permissão quando possível. Implemente o princípio do menor privilégio: a conta de banco de dados da aplicação deve ter apenas permissões necessárias.

CVE-2025-13210MEDIUMitsourcecode Inventory Management System index.php sql injectionEPSS 0.3%CVE-2025-8247MEDIUMProjectworlds Online Admission System admin.php sql injectionEPSS 0.3%CVE-2025-62697HIGHImproperly sanitized style parameter in LanguageSelectorEPSS 0.3%CVE-2026-2018MEDIUMitsourcecode School Management System controller.php sql injectionEPSS 0.3%CVE-2026-2012MEDIUMitsourcecode Student Management System index.php sql injectionEPSS 0.3%CVE-2026-2136MEDIUMprojectworlds Online Food Ordering System view-ticket.php sql injectionEPSS 0.3%CVE-2026-3616MEDIUMDefaultFuction Jeson Customer Relationship Management System edit.php sql injectionEPSS 0.3%CVE-2026-39419LOWMaxKB: Sandbox Result Validation Bypass via Tool Output SpoofingEPSS 0.3%CVE-2026-2057MEDIUMSourceCodester Medical Center Portal Management System login.php sql injectionEPSS 0.3%CVE-2026-9568LOWThingsBoard YAML provision getGatewayDockerComposeFile code injectionEPSS 0.3%CVE-2026-2011MEDIUMitsourcecode Student Management System controller.php sql injectionEPSS 0.3%CVE-2026-2060MEDIUMcode-projects Simple Blood Donor Management System editcampaignform.php sql injectionEPSS 0.3%CVE-2024-39320MEDIUMDiscourse allows iframe injection though default site settingEPSS 0.3%CVE-2025-11071MEDIUMSeaCMS Cron Task Management admin_cron.php sql injectionEPSS 0.3%CVE-2026-2195MEDIUMcode-projects Online Reviewer System questions-view.php sql injectionEPSS 0.3%CVE-2026-2197MEDIUMcode-projects Online Reviewer System exam-delete.php sql injectionEPSS 0.3%CVE-2026-2115MEDIUMitsourcecode Society Management System delete_expenses.php sql injectionEPSS 0.3%CVE-2026-2211MEDIUMcode-projects Online Music Site AdminDeleteCategory.php sql injectionEPSS 0.3%CVE-2026-2212MEDIUMcode-projects Online Music Site AdminEditCategory.php sql injectionEPSS 0.3%CVE-2026-2199MEDIUMcode-projects Online Reviewer System user-delete.php sql injectionEPSS 0.3%