A security flaw has been identified in specific versions of PHP, the software that powers most dynamic websites (including those with contact forms, user login systems, or content management tools). The issue is caused by improper handling of backslashes in data submitted by visitors to your site.
If exploited, this vulnerability could allow attackers to run unauthorized commands against your website's database. This could let them access, modify, or delete sensitive information such as customer data, login credentials, or published site content.
This flaw impacts PHP 8.2 versions older than 8.2.33, PHP 8.3 versions older than 8.3.33, PHP 8.4 versions older than 8.4.24, and PHP 8.5 versions older than 8.5.9.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-17543