Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-57744: Untrusted Data Can Inject Malicious Objects into RT-Theme 18
CVE-2026-57744 · published 2 months ago
Summary
The RT-Theme 18 | Extensions rt18-extensions may allow an attacker to inject malicious code by sending untrusted data. This affects websites using the affected extension. To protect your site, update the rt18-extensions to a version higher than 2.5.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| stmcan | rt-theme 18 | extensions | <= 2.5 |
Original advisory text
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published13 Jul 2026
Updated1 Oct 2026
First seen13 Jul 2026
Track software like this
Free during beta