OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-94683

HIGH · CVSS 8.8 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

DesignSetGo versions up to 2.8.0 are vulnerable to PHP Object Injection, which could allow an attacker to exploit the application by injecting malicious objects, potentially leading to remote code execution or data manipulation. Organizations using this software should prioritize patching or mitigating this vulnerability due to its high severity and the potential for significant impact on system integrity and confidentiality.

CVE
CVE-2026-94683
Severity
HIGH
CVSS
8.8
EPSS
0.36%

Original NVD Description

Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.