Django SQL Injection in cursor.execute()
CRITICALSQL injection vulnerability: User input flows to cursor.execute() without parameterization within a function. Use parameterized queries with %s placeholders.
Rule Information
Language
Python
Category
Django
Author
Code Pathfinder
Last Updated
2026-01-17
Tags
pythondjangosql-injectionormdatabaseowasp-a03cwe-89parameterizationcursorintra-proceduralcriticalsecurity
CWE References
CVE References