Rank 3 in the 2024 CWE Top 25 (frequency x severity of CVEs). SQL Injection: user input is incorporated into an SQL query without proper neutralisation, allowing modification of query logic and unauthorised data access.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.