Why You Should Care About SQL Injections in 2026 w/ Fernando Panizza

Why You Should Care About SQL Injections in 2026 w/ Fernando Panizza

Source: YouTube · Black Hills Information Security · published Jun 26, 2026 · 1:18:33

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

SQL injections remain highly relevant and dangerous in 2026, persisting as one of the most common web vulnerabilities despite decades of known mitigations 0:41-0:51.

Key Takeaways:
• SQL injection moved up to #2 on the MITRE CWE Top 25 in 2025, indicating the threat is growing, not declining 6:10-6:29
• Raw SQL query building with string concatenation remains vulnerable, and input validation can be bypassed—as demonstrated by the SuiteCRM CVE where an anti-XSS function inadvertently decoded sanitized payloads 10:06-10:15
• Prepared statements and ORMs are not silver bullets; unsanitized identifiers (like column names in ORDER BY clauses) bypass parameterization, as shown in the Meshery vulnerability 11:49-12:01
• Stored procedures can still be vulnerable if they use dynamic query building through concatenation instead of bound parameters 12:29-12:36
• Defending against SQLi requires a layered approach: developer training, input validation, prepared statements, WAFs, code reviews, and database hardening 1:02:56-1:03:05

A multi-layered defense strategy is essential because no single mitigation eliminates SQL injection risk entirely.

Sources:

  • 0:41-0:51 Speaker explains finding more SQLi vulnerabilities than expected in 2026
  • 6:10-6:29 SQLi ranking climb on MITRE CWE Top 25
  • 10:06-10:15 Why raw SQL query building remains dangerous
  • 11:49-12:01 Unsanitized identifiers bypass prepared statements
  • 12:29-12:36 Dynamic query building in stored procedures
  • 1:02:56-1:03:05 Recommended layered defense approach

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hey everybody, welcome to today's BHIS webcast. Why you should care about SQL injections in 2026 of all the years why why is that still a thing? Fernando's going to tell you why. And I'm going to go backstage. He's going to take over and we'll come back at the end for some Q&A. Fernando, take it away. >> Thanks. So hey everyone and thank you for joining. So at the idea behind the talk is because basically what originated this webcast was that uh I found myself finding more uh SQL injections vulnerabilities than I would expect to be finding in 2026 while doing penetration tests. So I thought that it was important to try to analyze why do do these vulnerabilities happen? And maybe providing some tips for penetration testers to um finding these types of vulnerabilities, especially if you're n…