OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102377

HIGH · CVSS 8.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A PHP Object Injection vulnerability exists in Photo Gallery by 10Web versions up to 1.8.46, allowing attackers to exploit the application by injecting malicious objects, potentially leading to remote code execution. This high-severity flaw poses significant risks to any installations of the affected software, particularly for those handling sensitive data or user-generated content. Organizations using this plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-102377
Severity
HIGH
CVSS
8.8
EPSS
0.29%

Original NVD Description

Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.