Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-57770: Grand Photography Untrusted Data Deserialization Risk
CVE-2026-57770
Summary
Grand Photography versions 5.7.8 and below are at risk of object injection attacks. This means an attacker could potentially inject malicious code into the application, leading to unauthorized actions or data access. Update to a secure version of Grand Photography to mitigate this risk.
Original title
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
Original description
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
nvd CVSS3.1
9.8
Vulnerability type
CWE-502
Deserialization of Untrusted Data
Published: 13 Jul 2026 · Updated: 17 Jul 2026 · First seen: 13 Jul 2026