|
3891
|
8.1 |
HIGH
Network
|
-
|
-
|
Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP (vulnerabilidad de 'Inclusión remota de ficheros PHP') en CreativeWS VintWood vintwood permite la Inclu…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32504
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3892
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS Kiddy kiddy allows PHP Local File Inclusion.This issue affects Kidd…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32505
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3893
|
8.1 |
HIGH
Network
|
-
|
-
|
Control inadecuado del nombre de fichero para la declaración include/require en un programa PHP (vulnerabilidad de 'inclusión remota de ficheros PHP') en CreativeWS Kiddy kiddy permite la inclusión l…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32505
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3894
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a through < 1.7.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32506
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3895
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Edge-Themes Archicon archicon permite la inyección de objetos. Este problema afecta a Archicon: desde n/a hasta < 1.7.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32506
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3896
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Elated-Themes Leroux leroux allows Object Injection.This issue affects Leroux: from n/a through < 1.4.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32507
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3897
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Elated-Themes Leroux leroux permite la inyección de objetos. Este problema afecta a Leroux: desde n/a hasta < 1.4.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32507
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3898
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue affects Halstein: from n/a through < 1.8.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32508
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3899
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Mikado-Themes Halstein halstein permite la inyección de objetos. Este problema afecta a Halstein: desde n/a hasta < 1.8.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32508
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3900
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects Gracey: from n/a through < 1.4.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32509
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|