CVE-2026-78535: Themerex Photolia

Critical severity, CVSS 9.8.

Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.

Affected products

  • Themerex Photolia: up to and including 1.0.3

Published 2026-10-10. Last modified 2026-10-10.