Form character limit request for prevent SQL injection ve XSS

Forms should have character limits in order to prevent SQL injection ve XSS. I talked with 3 different Hubspot support agent, they all suggest me an add Javascript code. Client-side solutions, like JS, cannot solve this problem since they can be easily evaded by only using the browser. So, HubSpot should provide a server-side solution that only you can provide.