Hibernate supports bound parameters, but HQL/JPQL assembled by string concatenation, native-SQL queries (createNativeQuery), and raw Restrictions.sqlRestriction fragments reintroduce SQL injection against the underlying JDBC backend. Attacker-controlled Criteria property or sort names are a related but distinct issue: Hibernate resolves them against mapped properties rather than splicing them into SQL, so they can expose unintended fields or ordering without being SQL injection.