sql-injection
Safeguard articles tagged "sql-injection" — guides, analysis, and best practices for software supply chain and application security.
74 articles
Your Application Connects as a User That Can Do Everything
A SQL injection is limited by what the connected user may do, and so is a compromised application process. In most deployments the answer is everything, because that is what the framework quickstart produced.
Second-Order SQL Injection Is the Bug Class a Scanner Should Refuse to Test
For a stored injection, confirming the bug and exploiting it are the same action. That is a property of the vulnerability, not a gap in anyone's product, and it changes what you should ask a DAST vendor.
MOVEit Transfer (CVE-2023-34362): A Mass Exploitation Data-Theft Campaign
A factual look at the 2023 Cl0p ransomware group campaign exploiting a SQL injection vulnerability in Progress Software MOVEit Transfer to steal data from hundreds of organizations.
A Critical SQL Injection in Drupal Core's Database Abstraction Layer Is Being Actively Exploited
CVE-2026-9082 hits the shared database abstraction API every Drupal module and query routes through, confirmed exploited just two days after Drupal's own security advisory.
LiteLLM's AI Gateway Shipped a Critical SQL Injection and a Command Injection in the Same Patch Cycle
An unauthenticated SQL injection in API key checks and an authenticated command injection via MCP preview endpoints both hit BerriAI's LiteLLM proxy, fixed together in v1.83.7.
Sangoma Switchvox's Phone-Provisioning Feature Was an Unauthenticated SQL Injection
CVE-2026-9586 abuses Switchvox's Polycom phone-provisioning endpoint, concatenating device-submitted XML directly into a SQL query with no authentication required.
Metabase's Password Reset Endpoint Was a CVSS 10.0 SQL Injection
CVE-2026-72898 lets an unauthenticated attacker inject SQL through Metabase's own password-reset flow and gain full administrator access to the connected BI instance.
Two WordPress CVEs, and NVD Says They're the Same Attack Chain
WordPress core's CVE-2026-63030 explicitly references CVE-2026-60137 in its own NVD description — a documented exploitation chain, not two coincidentally similar bugs.
Django QuerySet.explain SQL injection (CVE-2022-28346)
A Django ORM flaw let unvalidated input reach EXPLAIN and annotate() SQL generation. Here's the CVE-2022-28347 impact, fix, and defense playbook.
Django GIS SQL injection (CVE-2020-9402)
CVE-2020-9402 lets attackers inject SQL via Django GIS's tolerance parameter on Oracle. Versions, CVSS/EPSS data, timeline, and fixes inside.
SQL injection: a complete developer's guide
A developer's guide to SQL injection: how it works, why CWE-89 still ranks in MITRE's Top 25, real breaches, and how to detect and fix it.
SQL Injection Cheatsheet: Detection and Prevention for Developers
A defender's SQL injection cheatsheet: how the vulnerability class works, how to recognize it in code, and the patterns that reliably shut it down.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.