CVE-2026-17543 (matched: php)

  • Wednesday, 5th August, 2026
  • 22:04pm

A security flaw has been identified in specific versions of PHP, the software that powers most dynamic, interactive websites. The issue affects PHP 8.2 versions older than 8.2.33, 8.3 versions older than 8.3.33, 8.4 versions older than 8.4.24, and 8.5 versions older than 8.5.9. It is caused by improper handling of backslashes in input submitted by visitors to your site. This flaw makes SQL injection attacks very easy to carry out. These attacks let bad actors run unauthorized commands on your website's database. If exploited, this could allow attackers to access, modify, or delete sensitive data stored on your site, such as customer records, login credentials, or published content.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-17543

« Back