PatchSiren

rascals CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH rascals CVE published 2026-10-10

CVE-2026-62021

A PHP object injection vulnerability exists in the Angio theme, version 1.1.1 or earlier. This issue allows a subscriber to inject malicious PHP objects, potentially leading to arbitrary code execution.