PoC Archive PoC Archive

tag

Php-Object-Injection

GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
CVE-2025-22777 web Patched
CVE-2025-22777webCRITICAL 9.8Patched2026-07-06WP Zendesk for Contact Form 7 Unauthenticated PHP Object Injection (CVE-2026-49105)
CVE-2026-49105 web Unverified
CVE-2026-49105webHIGH 8.1Unverified2026-07-05WP Insightly Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49085)
CVE-2026-49085 web Unverified
CVE-2026-49085webHIGH 8.1Unverified2026-07-05WP Activity Log Unauthenticated PHP Object Injection — CVE-2026-54806
CVE-2026-54806 web Patched
CVE-2026-54806webCRITICAL 9.8Patched2026-07-05SP LMS PHP Object Injection → Unauthenticated RCE (CVE-2026-48909)
CVE-2026-48909 (GHSA-gf8c-xmwj-whrh) web Patched
CVE-2026-48909webCRITICAL 9.5Patched2026-07-05Integration for Keap/Infusionsoft Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49104)
CVE-2026-49104 web Unverified
CVE-2026-49104webHIGH 8.1Unverified2026-07-05Integration for ActiveCampaign Unauthenticated PHP Object Injection via Unsafe Deserialization (CVE-2026-9691)
CVE-2026-9691 web Unpatched
CVE-2026-9691webHIGH 8.1Unpatched2026-07-05Everest Forms Unauthenticated PHP Object Injection to RCE (CVE-2026-3296)
CVE-2026-3296 web Patched
CVE-2026-3296webCRITICAL 9.8Patched2026-07-05Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247) KEV EPSS 28%
CVE-2026-45247 web Unverified
CVE-2026-45247webCRITICAL 9.3Unverified2026-07-01