CVE-2026-87719
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that
CVSS
9.9
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 12 sept 2026 · Última mod.: 12 sept 2026 · CWE-502
Sin historial EPSS suficiente todavía.
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-621078.8 ALT—
———Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.15hCVE-2026-621059.8 CRÍ—
———Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.15hCVE-2026-621039.8 CRÍ—
———Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.15hCVE-2026-736997.2 ALT—
——0FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required named-key array to disable class instantiation. Attackers with database write access can inject a serialized gadget chain into the permissions table columns processed on every authenticated page load to write arbitrary files, such as PHP webshells, to web-accessible paths.2dCVE-2026-817848.1 ALT—
——0Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.2dCVE-2026-829258.1 ALT21.2%
——6The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its sample value, or too short to be secret. This allows unauthenticated users to inject arbitrary PHP objects on such installs. The Site Reviews WordPress plugin before 8.3.0's own code contains no chain onward from the injected object, so how far it reaches depends on the other code present on the site.2d