CVE-2026-62105
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
CVSS
9.8
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 11 sept 2026 · Última mod.: 11 sept 2026 · CWE-502
Sin historial EPSS suficiente todavía.
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-621078.8 ALT—
———Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.8hCVE-2026-621039.8 CRÍ—
———Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.8hCVE-2026-736997.2 ALT—
——0FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required named-key array to disable class instantiation. Attackers with database write access can inject a serialized gadget chain into the permissions table columns processed on every authenticated page load to write arbitrary files, such as PHP webshells, to web-accessible paths.1dCVE-2026-817848.1 ALT—
——0Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.1dCVE-2026-829258.1 ALT21.2%
——6The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its sample value, or too short to be secret. This allows unauthenticated users to inject arbitrary PHP objects on such installs. The Site Reviews WordPress plugin before 8.3.0's own code contains no chain onward from the injected object, so how far it reaches depends on the other code present on the site.2dCVE-2026-578226.5 MED6.7%
——2When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.2d