CRITICAL 9.8 CVE-2026-78535 Published 10 Oct 2026

Photolia Plugin PHP Object Injection Vulnerability

Worried this affects your website?

A vulnerability has been found in Photolia versions <= 1.0.3. The flaw is an unauthenticated PHP Object Injection vulnerability.

  • Affected versions: Photolia <= 1.0.3
  • Authentication: None required
  • Vulnerability type: PHP Object Injection

Reference: CVE-2026-78535 on NVD

← Back to Security News