Safeguard
Tag

sql-injection

Safeguard articles tagged "sql-injection" — guides, analysis, and best practices for software supply chain and application security.

74 articles

Application Security

Your Application Connects as a User That Can Do Everything

A SQL injection is limited by what the connected user may do, and so is a compromised application process. In most deployments the answer is everything, because that is what the framework quickstart produced.

Sep 18, 20266 min read
Application Security

Second-Order SQL Injection Is the Bug Class a Scanner Should Refuse to Test

For a stored injection, confirming the bug and exploiting it are the same action. That is a property of the vulnerability, not a gap in anyone's product, and it changes what you should ask a DAST vendor.

Sep 17, 20267 min read
Vulnerability Analysis

MOVEit Transfer (CVE-2023-34362): A Mass Exploitation Data-Theft Campaign

A factual look at the 2023 Cl0p ransomware group campaign exploiting a SQL injection vulnerability in Progress Software MOVEit Transfer to steal data from hundreds of organizations.

Sep 17, 20262 min read
Vulnerability Analysis

A Critical SQL Injection in Drupal Core's Database Abstraction Layer Is Being Actively Exploited

CVE-2026-9082 hits the shared database abstraction API every Drupal module and query routes through, confirmed exploited just two days after Drupal's own security advisory.

Sep 16, 20265 min read
Vulnerability Analysis

LiteLLM's AI Gateway Shipped a Critical SQL Injection and a Command Injection in the Same Patch Cycle

An unauthenticated SQL injection in API key checks and an authenticated command injection via MCP preview endpoints both hit BerriAI's LiteLLM proxy, fixed together in v1.83.7.

Sep 16, 20265 min read
Vulnerability Analysis

Sangoma Switchvox's Phone-Provisioning Feature Was an Unauthenticated SQL Injection

CVE-2026-9586 abuses Switchvox's Polycom phone-provisioning endpoint, concatenating device-submitted XML directly into a SQL query with no authentication required.

Sep 16, 20264 min read
Vulnerability Analysis

Metabase's Password Reset Endpoint Was a CVSS 10.0 SQL Injection

CVE-2026-72898 lets an unauthenticated attacker inject SQL through Metabase's own password-reset flow and gain full administrator access to the connected BI instance.

Sep 16, 20264 min read
Vulnerability Analysis

Two WordPress CVEs, and NVD Says They're the Same Attack Chain

WordPress core's CVE-2026-63030 explicitly references CVE-2026-60137 in its own NVD description — a documented exploitation chain, not two coincidentally similar bugs.

Sep 16, 20264 min read
Vulnerability Analysis

Django QuerySet.explain SQL injection (CVE-2022-28346)

A Django ORM flaw let unvalidated input reach EXPLAIN and annotate() SQL generation. Here's the CVE-2022-28347 impact, fix, and defense playbook.

Aug 8, 20267 min read
Vulnerability Analysis

Django GIS SQL injection (CVE-2020-9402)

CVE-2020-9402 lets attackers inject SQL via Django GIS's tolerance parameter on Oracle. Versions, CVSS/EPSS data, timeline, and fixes inside.

Aug 8, 20267 min read
Vulnerability Analysis

SQL injection: a complete developer's guide

A developer's guide to SQL injection: how it works, why CWE-89 still ranks in MITRE's Top 25, real breaches, and how to detect and fix it.

Aug 3, 20267 min read
AppSec

SQL Injection Cheatsheet: Detection and Prevention for Developers

A defender's SQL injection cheatsheet: how the vulnerability class works, how to recognize it in code, and the patterns that reliably shut it down.

Jul 17, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.