Aqua theme version 5.1.2 and earlier is vulnerable to PHP Local File Inclusion. This issue, CVE-2026-57789, has a CVSS score of 7.5 and is classified as HIGH severity. The vulnerability is caused by improper control of filename for include/require statement in PHP program. The Aqua theme's vulnerability allows attackers to include local files, potentially leading to code execution. Users of the Aqua theme [truncated]
CVE-2026-42380 is a critical vulnerability in AI Lab versions before 5.4.2, allowing unauthenticated PHP object injection. The vulnerability has a CVSS score of 9.8 and is considered critical. This vulnerability affects AI Lab versions before 5.4.2 and allows attackers to inject malicious PHP objects, potentially leading to arbitrary code execution. Administrators and users should be aware of this vulnera [truncated]