Php · Php · CVE-2026-17543
**Name of the Vulnerable Software and Affected Versions**
PHP versions 8.2.0 through 8.2.32
PHP versions 8.3.0 through 8.3.32
PHP versions 8.4.0 through 8.4.23
PHP versions 8.5.0 through 8.5.8
**Description**
Improper escaping of backslashes in attacker-provided parameters allows for SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution.
**Recommendations**
Update PHP versions 8.2.0 through 8.2.32 to version 8.2.33.
Update PHP versions 8.3.0 through 8.3.32 to version 8.3.33.
Update PHP versions 8.4.0 through 8.4.23 to version 8.4.24.
Update PHP versions 8.5.0 through 8.5.8 to version 8.5.9.