Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-57744: Untrusted Data Can Inject Malicious Objects into RT-Theme 18

CVE-2026-57744 · published 2 months ago
Summary

The RT-Theme 18 | Extensions rt18-extensions may allow an attacker to inject malicious code by sending untrusted data. This affects websites using the affected extension. To protect your site, update the rt18-extensions to a version higher than 2.5.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
stmcan rt-theme 18 | extensions <= 2.5
Original advisory text
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published13 Jul 2026
Updated1 Oct 2026
First seen13 Jul 2026
Sources
CVE-2026-57744 · MITRE
Track software like this
Free during beta