Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-57744: Untrusted Data Can Inject Malicious Objects into RT-Theme 18
CVE-2026-57744
CVE-2026-57744
Summary
The RT-Theme 18 | Extensions rt18-extensions may allow an attacker to inject malicious code by sending untrusted data. This affects websites using the affected extension. To protect your site, update the rt18-extensions to a version higher than 2.5.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| stmcan | rt-theme 18 | extensions | <= 2.5 |
Original title
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
Original description
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
nvd CVSS3.1
9.8
Vulnerability type
CWE-502
Deserialization of Untrusted Data
Published: 13 Jul 2026 · Updated: 18 Jul 2026 · First seen: 13 Jul 2026