Skip to content
Threat Feed

Tag

Php-Injection

4 briefs RSS
high advisory

CVE-2026-17086 PHP Object Injection in ShortPixel Image Optimizer

Authenticated attackers can exploit insecure deserialization in ShortPixel Image Optimizer versions 6.5.5 and below to execute arbitrary code if a POP chain is available via other plugins or themes.

ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF wordpress vulnerability php-injection deserialization
1t 1c
high advisory

PHP Object Injection in Tutor LMS Plugin for WordPress

Tutor LMS plugin versions up to 4.0.7 are vulnerable to remote code execution via PHP object injection in the tutor_save_withdraw_account AJAX handler, allowing attackers to leverage POP chains.

Tutor LMS wordpress rce php-injection vulnerability
1r 1t 1c
high advisory

Pimcore Unrestricted Deserialization via Object-Store Columns

Pimcore components including Hotspotimage, ImageGallery, Block, and Video perform insecure PHP deserialization on database-stored metadata, enabling remote code execution via object injection.

Pimcore php-injection deserialization rce
1t
critical advisory

Froxlor PHP Code Injection via Unescaped Single Quotes in userdata.inc.php

Froxlor is vulnerable to PHP code injection due to unescaped single quotes in the userdata.inc.php generation via the MysqlServer API, where an administrator with `change_serversettings` permission can inject arbitrary PHP code, leading to arbitrary OS command execution as the web server user.

Froxlor php-injection webserver
2r 2t