User-supplied data interpreted as code or commands: SQL injection, OS command injection, XSS, and template injection.