Posts tagged

Backslash-Breakout
← Back to all posts
HB

E is for Exploit: CVE-2026-17543 — SQL Injection in PHP's pgsql Extension via the `E'...'` Backslash Breakout

On July 30, 2026, NIST’s National Vulnerability Database published CVE-2026-17543, a SQL injection vulnerability sitting not in some neglected WordPress plugin, but in PHP itself — specifically the pgsql extension that ships with the language. NVD scores it 9.8 Critical (C…