What potential pitfalls should be avoided when using PHP to generate HTML tables from database queries?

One potential pitfall to avoid when using PHP to generate HTML tables from database queries is SQL injection. To prevent this, always use prepared statements when querying the database.

$stmt = $pdo->prepare("SELECT * FROM table_name WHERE column_name = :value");
$stmt->bindParam(':value', $value);
$stmt->execute();
$results = $stmt->fetchAll();
```

Another pitfall to avoid is not properly escaping user input when outputting it in the HTML table. This can lead to cross-site scripting (XSS) attacks. To prevent this, use functions like `htmlspecialchars()` to escape the user input before outputting it.

```php
echo "<table>";
foreach ($results as $row) {
    echo "<tr>";
    echo "<td>" . htmlspecialchars($row['column_name']) . "</td>";
    echo "</tr>";
}
echo "</table>";