Thanks for clarifying!
Wow those are interesting.
SQL Injection is still an issue if there are string concats every where and calling the DB, so that is something, that can still happen.