CVE-2026-17543 (matched: php)

  • Thursday, 6th August, 2026
  • 16:05pm

A security flaw has been found in specific versions of PHP, the common software that powers interactive features on many websites, including contact forms, user login systems, and content management tools. The issue stems from improper handling of backslashes in inputs provided by website visitors, such as form submissions or URL parameters.

If exploited, this flaw could allow attackers to perform SQL injection, a type of attack that lets bad actors send unauthorized commands to your website’s database. This could potentially lead to unauthorized access to, modification of, or deletion of data stored on your site, including customer information, user account details, or published content.

The affected PHP versions are 8.2 releases older than 8.2.33, 8.3 releases older than 8.3.33, 8.4 releases older than 8.4.24, and 8.5 releases older than 8.5.9.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-17543

« Back