CVE-2026-17543

SQL injection in ext-pgsql via E'...' backslash breakout

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.


We have discovered 2,423,664 live websites that are affected by CVE-2026-17543.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains2,423,664 live websites (34% of PHP install base)
Vulnerable Versions
  • from 8.2 through 8.2.33
  • from 8.3 through 8.3.33
  • from 8.4 through 8.4.24
  • from 8.5 through 8.5.9
Vulnerable Versions Count99 versions ( 19% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • ExPatch-LLC (finder)
  • Alexandre Daubois - The PHP Foundation (analyst)
  • Ilija Tovilo - The PHP Foundation (remediation developer)
  • Matteo Beccati (remediation reviewer)
  • Jakub Zelenka - The PHP Foundation (remediation reviewer)

Website Distribution by Country

Number of websites using CVE-2026-17543
United States449,182 websites



Germany458,950 websites
France174,804 websites
Netherlands168,715 websites
GB119,520 websites
Cyprus93,758 websites
Denmark80,262 websites
Sweden73,919 websites
Japan70,776 websites
Russia69,744 websites

Website Distribution by TLD

Number of websites using CVE-2026-17543
.com844,263 websites
.de305,933 websites
.nl146,343 websites
.org92,921 websites
.co.uk76,523 websites
.fr75,713 websites
.se67,391 websites
.net64,782 websites
.ru60,013 websites
.it44,880 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-17543

Top websites that are affected by CVE-2026-17543. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com United States***
******.com United States***
*****.com United States***
**************.de Germany***
**********.de Germany***
***.******.com United States***
********.com United States***
******.org United States***
************.com United States***
***************.net United States***
See full domain list

FAQ

CVE-2026-17543 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in PHP
A total of 2,423,664 websites have been identified as vulnerable to CVE-2026-17543, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2026-17543 vulnerability.
PHP versions up to 8.5.9 are vulnerable to CVE-2026-17543.
CVE-2026-17543 is resolved in version 8.5.9 of PHP.