CVE-2026-66564: Themerex Shiftcv

Critical severity, CVSS 9.8.

Unauthenticated PHP Object Injection in ShiftCV <= 3.0.14 versions.

Affected products

  • Themerex Shiftcv: up to and including 3.0.14

Published 2026-10-10. Last modified 2026-10-10.