CVE-2026-73364
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
CVSS
9.8
Critical
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Published: Aug 19, 2026 · Last modified: Aug 20, 2026 · CWE-502
0.3%EPSS · 30 days0.3%
2026-08-202026-09-10
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-877199.9 CRI—
———GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.7hCVE-2026-621078.8 HIG—
———Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.13hCVE-2026-621059.8 CRI—
———Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.13hCVE-2026-621039.8 CRI—
———Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.13hCVE-2026-736997.2 HIG—
——0FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required named-key array to disable class instantiation. Attackers with database write access can inject a serialized gadget chain into the permissions table columns processed on every authenticated page load to write arbitrary files, such as PHP webshells, to web-accessible paths.2dCVE-2026-817848.1 HIG—
——0Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.2d