Skip to content

What is SQL injection?

Also called: SQLi

The short answer

SQL injection is an attack that slips database commands into form fields or URLs, letting an attacker read or change data the site never meant to expose.

SQL injection, explained

Parameterised queries, which keep data separate from commands, prevent it completely.

Questions people ask about SQL injection

What is SQL injection?

SQL injection is an attack that slips database commands into form fields or URLs, letting an attacker read or change data the site never meant to expose.

Part of the Web Encyclopedia by Apex Flow Digital. Definitions are general knowledge, kept current, with no invented statistics.

Reviews

We’re early. Real reviews only.

Apex Flow Digital launched recently. Every purchase comes with a request for honest feedback through our help center. When real buyers write real reviews, they go here — with their permission, by name. Until then, this section stays empty. No fakes. No stock photos. No bullshit.

Used something from the catalog? Leave honest feedback →

While you’re here…