CVE-2025-64114: Php Unparameterized Sql Query
User input is directly interpolated or concatenated into a SQL query string passed to a database execution method. This can lead to SQL injection vulnerabilities. Use prepared statements and parameter binding instead of directly constructing SQL queries with user data. When identifiers like table or column names must be dynamic, validate them against a stric
greprules fetch cve-2025-64114-php-unparameterized-sql-query --engine opengrepDescription
User input is directly interpolated or concatenated into a SQL query string passed to a database execution method. This can lead to SQL injection vulnerabilities. Use prepared statements and parameter binding instead of directly constructing SQL queries with user data. When identifiers like table or column names must be dynamic, validate them against a stric
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.