PT-2026-66457 · Php+2 · Php+2

·

CVE-2026-17543

·

Published

2026-07-30

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions 8.2.0 through 8.2.32 PHP versions 8.3.0 through 8.3.32 PHP versions 8.4.0 through 8.4.23 PHP versions 8.5.0 through 8.5.8
Description Improper escaping of backslashes in attacker-provided parameters allows for SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution.
Recommendations Update PHP versions 8.2.0 through 8.2.32 to version 8.2.33. Update PHP versions 8.3.0 through 8.3.32 to version 8.3.33. Update PHP versions 8.4.0 through 8.4.23 to version 8.4.24. Update PHP versions 8.5.0 through 8.5.8 to version 8.5.9.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:56969
ALSA-2026:57539
ALSA-2026:57574
ALSA-2026:61259
ALSA-2026:61903
ALSA-2026:62334
ALSA-2026:62614
AZL-94178
BIT-LIBPHP-2026-17543
BIT-PHP-2026-17543
BIT-PHP-MIN-2026-17543
CVE-2026-17543
OESA-2026-3475
OPENSUSE-SU-2026:11418-1
OPENSUSE-SU-2026:21532-1
RHSA-2026:47200
RHSA-2026:56969
RHSA-2026:57539
RHSA-2026:57574
RHSA-2026:61903
RHSA-2026:62334
SUSE-SU-2026:23121-1
SUSE-SU-2026:23144-1
SUSE-SU-2026:3509-1
SUSE-SU-2026:3510-1
SUSE-SU-2026:3513-1
SUSE-SU-2026:3514-1
USN-8734-1
USN-8743-1

Affected Products

Php
Rocky Linux
Ubuntu