SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-17543

CRITICAL · CVSS 9.8 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

PHP versions 8.2.* prior to 8.2.33, 8.3.* prior to 8.3.33, 8.4.* prior to 8.4.24, and 8.5.* prior to 8.5.9 are vulnerable due to improper escaping of backslashes in user-supplied parameters, leading to potential SQL injection attacks. This vulnerability could allow attackers to manipulate database queries, resulting in unauthorized data access or modification. Organizations using these PHP versions should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-17543
Severity
CRITICAL
CVSS
9.8
EPSS
0.32%

Original NVD Description

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

Related CVEs

Other vulnerabilities affecting the same vendor(s)