Tag
CVE-2026-17086 PHP Object Injection in ShortPixel Image Optimizer
1 TTP 1 CVEAuthenticated attackers can exploit insecure deserialization in ShortPixel Image Optimizer versions 6.5.5 and below to execute arbitrary code if a POP chain is available via other plugins or themes.
PHP Object Injection in Tutor LMS Plugin for WordPress
1 rule 1 TTP 1 CVETutor LMS plugin versions up to 4.0.7 are vulnerable to remote code execution via PHP object injection in the tutor_save_withdraw_account AJAX handler, allowing attackers to leverage POP chains.
Pimcore Unrestricted Deserialization via Object-Store Columns
1 TTPPimcore components including Hotspotimage, ImageGallery, Block, and Video perform insecure PHP deserialization on database-stored metadata, enabling remote code execution via object injection.
Froxlor PHP Code Injection via Unescaped Single Quotes in userdata.inc.php
2 rules 2 TTPsFroxlor is vulnerable to PHP code injection due to unescaped single quotes in the userdata.inc.php generation via the MysqlServer API, where an administrator with `change_serversettings` permission can inject arbitrary PHP code, leading to arbitrary OS command execution as the web server user.