CVE-2026-66483: Themerex Education Center

Critical severity, CVSS 9.8.

Unauthenticated PHP Object Injection in Education Center <= 3.6.12 versions.

Affected products

  • Themerex Education Center: up to and including 3.6.12

Published 2026-10-10. Last modified 2026-10-10.