PatchSiren

JanStudio CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH JanStudio CVE published 2026-01-07

CVE-2025-69080

A PHP Remote File Inclusion vulnerability exists in JanStudio Gecko theme version 1.9.8 and earlier. This issue allows attackers to include local files via a manipulated filename. Defenders should assess exposure, particularly those managing PHP applications and WordPress themes. The vulnerability's impact on confidentiality, integrity, and availability is rated high with a CVSS score of 8.1.