There are two obvious SQL injections in there.
@svedrin I'm not managing this repo, remove the webhook or contact me in Slack //cc @yegor256