CVE-2026-66563: Themerex Windsor

Critical severity, CVSS 9.8.

Unauthenticated PHP Object Injection in Windsor <= 2.10 versions.

Affected products

  • Themerex Windsor: up to and including 2.10

Published 2026-10-10. Last modified 2026-10-10.