# TaintedSql Emitted when user-controlled input can be passed into to a xpath query. ```php xpath($expression); } ```