CVE-2026-10721
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components.
CVSS
—
Sin CVSS
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Publicado: 10 jun 2026 · Última mod.: 23 jul 2026 · CWE-502
0.1%EPSS · 30 días0.1%
2026-06-302026-07-26
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 for reporting.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-159628.8 ALT30.8%
——9The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.1dCVE-2026-505179.9 CRÍ66.4%
——20Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.2dCVE-2026-21655—6.1%
——2Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586.
This issue affects victor: from 2.9 before 3.0.3dCVE-2026-654977.2 ALT29.6%
——9Administrator PHP Object Injection in Complianz <= 7.5.0 versions.4dCVE-2026-654937.5 ALT29.9%
——9Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.4dCVE-2026-595449.8 CRÍ23.7%
——7Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.4d