CWE-564 SQL注入:Hibernate 类弱点 7 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-564 指在使用 Hibernate 框架执行动态 SQL 语句时,若直接拼接用户可控输入,会导致 SQL 注入漏洞。攻击者通过构造恶意输入,可篡改查询逻辑或执行任意 SQL 命令,从而窃取或破坏数据。开发者应避免直接拼接字符串,转而使用参数化查询或预编译语句,确保用户输入被正确转义,从而有效防御此类攻击。
String street = getStreetFromUser(); Query query = session.createQuery("from Address a where a.street='" + street + "'");| CVE ID | タイトル | CVSS | 深刻度 | 公開日 |
|---|---|---|---|---|
| CVE-2026-4594 | erupts erupt EruptJpaUtils.java geneEruptHqlOrderBy sql injection — erupt | 7.3 | High | 2026-03-23 |
| CVE-2026-4593 | erupts erupt MCP Tool EruptDataQuery.java EruptDataQuery sql injection — erupt | 6.3 | Medium | 2026-03-23 |
| CVE-2026-23959 | CoreShop Vulnerable to SQL Injection via Admin customer-company-modifier — CoreShop | 4.9AI | MediumAI | 2026-01-22 |
| CVE-2026-22242 | CoreShop Vulnerable to SQL Injection via Admin Reports — CoreShop | 4.9 | Medium | 2026-01-08 |
| CVE-2025-8052 | HQL Injection vulnerability has been discovered in Opentext Flipper. — Flipper | 8.1AI | HighAI | 2025-10-20 |
| CVE-2024-48988 | Apache StreamPark: SQL injection vulnerability — Apache StreamPark | 9.8 | - | 2025-08-22 |
| CVE-2025-0959 | Eventer - WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_id — Eventer - WordPress Event & Booking Manager Plugin | 8.8 | High | 2025-03-07 |
CWE-564(SQL注入:Hibernate) 是常见的弱点类别,本平台收录该类弱点关联的 7 条 CVE 漏洞。