Vulnerability
CVE-2026-17543
CVE-2026-17543 is a critical-severity vulnerability (CVSS v3.1 9.8). As of 2026-10-08, 36 458 hosts in our data show software it affects on an open service in at least 15 countries.
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
- Published
- 2026-07-30
- Last modified
- 2026-08-05
- CVSS score
- 9.8 CVSS v3.1
- CVSS vector (v3.1)
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploit likelihood (EPSS)
- 0.3% in the next 30 days (higher than 24% of CVEs)
Exposure in our data
36 458 hosts
Hosts whose banner shows an affected software version on a service open at their latest check.
Not counted: 9 hosts with this CVE only from an older observation.
Not counted: 6 hosts where the software version is too vague to tell (only a major release).
Not counted: 956 more on distribution builds that may be patched (the distribution may have backported the fix without changing the version).
14 more hosts had it earlier (the software version has since changed or the service is gone).
Counted 2026-10-08 03:20 UTC
By country
| Netherlands NL | 6 836 |
| United States US | 6 743 |
| Germany DE | 5 504 |
| United Kingdom GB | 1 369 |
| Romania RO | 1 321 |
| India IN | 1 311 |
| France FR | 1 278 |
| Japan JP | 1 260 |
| China CN | 1 076 |
| Hong Kong HK | 746 |
| Bulgaria BG | 712 |
| Russia RU | 679 |
| Italy IT | 554 |
| Singapore SG | 527 |
| Spain ES | 417 |
Affected software seen
| php 8.2.8 | 7 734 |
| php 8.3.31 | 2 954 |
| php 8.2.12 | 2 772 |
| php 8.2.30 | 1 770 |
| php 8.2.31 | 1 651 |
| php 8.3.30 | 1 648 |
| php 8.3.32 | 1 387 |
| php 8.2.29 | 1 384 |
| php 8.2.28 | 1 032 |
| php 8.4.21 | 965 |
| php 8.3.28 | 691 |
| php 8.5.5 | 570 |