CVE-2026-17543 (matched: php)

  • Saturday, 8th August, 2026
  • 10:04am

A security flaw has been identified in specific versions of PHP, the software that powers most interactive, database-driven websites. The issue is caused by incorrect handling of backslash characters in inputs submitted by visitors to your site. This flaw lets bad actors slip unauthorized commands into your website’s database queries, a common attack type called SQL injection. If exploited, attackers could access, modify, or delete sensitive data stored on your site, such as customer details, private content, or transaction records. The affected PHP versions are all 8.2 releases older than 8.2.33, all 8.3 releases older than 8.3.33, all 8.4 releases older than 8.4.24, and all 8.5 releases older than 8.5.9.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-17543

« Back