CVE-2026-62090: Themerex Wineshop

Critical severity, CVSS 9.8.

Unauthenticated PHP Object Injection in WineShop <= 3.20 versions.

Affected products

  • Themerex Wineshop: up to and including 3.20

Published 2026-10-10. Last modified 2026-10-10.