PatchSiren

WebAppick CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WebAppick CVE published 2026-06-15

CVE-2026-39434

A high-severity vulnerability, CVE-2026-39434, was discovered in the CTX Feed plugin, affecting versions up to 6.6.26. This vulnerability allows shop managers to inject PHP objects, potentially leading to code execution, data breaches, or other malicious activities. The CVSS score for this vulnerability is 7.2, indicating a high level of severity.