How to write a rule to prevent script injection?

I am going to prevent code injection (SQL, XML, etc.) on my website. What is the expression rule that I should use?

A firewall rule won’t do it, this is a feature of the CF WAF which is included in the Pro, Business, and Enterprise plans.

