Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.1

ThemeREX Printy: Malicious Files Can Be Injected

CVE-2026-28035
Summary

A security flaw in ThemeREX Printy allows attackers to inject and execute malicious files on your website. This can happen if an attacker is able to trick the system into including their own PHP code. To protect your website, update to the latest version of ThemeREX Printy or consider replacing it with a more secure alternative.

Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Printy printy allows PHP Local File Inclusion.This issue affects Pr...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Printy printy allows PHP Local File Inclusion.This issue affects Printy: from n/a through <= 1.8.
nvd CVSS3.1 8.1
Vulnerability type
CWE-98 Improper Control of Filename for Include
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026