Are there any potential security risks associated with using _SERVER["REQUEST_URI"] to get the complete URL in PHP?

Using _SERVER["REQUEST_URI"] to get the complete URL in PHP can pose a security risk as it directly exposes user input and can be manipulated for malicious purposes like SQL injection or cross-site scripting attacks. To mitigate this risk, it is recommended to sanitize and validate the input before using it in your code.

$url = filter_var($_SERVER["REQUEST_URI"], FILTER_SANITIZE_URL);