SQL query built with % formatting or .format() may allow injection.
Use parameterized queries with ? or %s placeholders instead of string formatting.