← Back to the live CVE advisory feed

CVE-2026-93944: Camelia

Severity
9.8 (CRITICAL)
Vendor
THEMEREX GROUP
Affected versions
0 through 1.2.15
Patch status
Unknown
Published
2026-10-10T08:17:06.930
Modified
2026-10-10T08:17:06.930

Why it matters

Critical vulnerability requiring immediate validation against your environment.

Recommended admin actions

  • Prioritize validation immediately due to critical CVSS severity.
  • Compare installed versions against the affected version range in the advisory.

Technical summary

Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 10, 2026 12:00 PM UTC
341 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-108263
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-85531
Product identification pending PATCH
Reporter: ILETISIM
9.8
CRITICAL
VIEW RECORD
CVE-2026-86405
Product identification pending PATCH
Reporter: ILETISIM
9.8
CRITICAL
VIEW RECORD
CVE-2026-108474
Product identification pending PATCH
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-104732
Advanced IP Blocker
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-94589
Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection)
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-103889
3D Product configurator for WooCommerce
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-104803
WPCOM Member
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-62045
Booklovers
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62046
Gutentype
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93927
Veto
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93929
Travesia
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93930
Tantra
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93931
Smash
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93932
Smart Casa
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93933
Rosalinda
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93934
Partiso
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93935
Let's Play
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93936
IPharm
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93937
Hygia
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93938
Hogwords
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93940
Greeny
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93941
Edema
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93942
Dwell
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93943
Convex
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93944
Camelia
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93945
Balance
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-107806
nginx-ui PATCH
Reporter: SECURITY-ADVISORIES
9.4
CRITICAL
VIEW RECORD
CVE-2026-100730
Product identification pending
Reporter: ICS-CERT
9.3
CRITICAL
VIEW RECORD
CVE-2026-105278
Product identification pending
Reporter: ICS-CERT
9.3
CRITICAL
VIEW RECORD
CVE-2026-108107
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-108109
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-15340
Product identification pending
Reporter: ICS-CERT
9.3
CRITICAL
VIEW RECORD
CVE-2026-28745
Product identification pending
Reporter: ICS-CERT
9.3
CRITICAL
VIEW RECORD
CVE-2026-33367
Product identification pending
Reporter: ICS-CERT
9.3
CRITICAL
VIEW RECORD
CVE-2026-39460
Product identification pending
Reporter: ICS-CERT
9.3
CRITICAL
VIEW RECORD
CVE-2026-107824
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-107845
contao PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-108261
tinacms PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-32645
Product identification pending
Reporter: ICS-CERT
9.2
CRITICAL
VIEW RECORD
CVE-2026-108157
Product identification pending PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-108264
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108265
enclave-os-mini PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108266
rustls PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108267
go PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108268
enclave-os-virtual PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108269
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-107645
Blocksy Companion
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-97670
Avada (Fusion) Builder
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-104801
PPOM – Product Addons & Custom Fields for WooCommerce
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-103412
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-103413
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-104392
Product identification pending
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-94064
Neo | Barber Shop WordPress Theme
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-94065
Product identification pending
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-107807
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-107809
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-107811
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-107813
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55797
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-104723
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-104725
Groundhogg — CRM, Newsletters, and Marketing Automation
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-104766
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-77183
FooSales – Point of Sale (POS) for WooCommerce
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-83526
FV Player 8
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-105281
Product identification pending
Reporter: ICS-CERT
8.7
HIGH
VIEW RECORD
CVE-2026-108106
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-104084
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-108113
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-104082
Product identification pending
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-8374
Product identification pending
Reporter: A341C0D1-EBF7-493F-A84E-38CF86618674
8.5
HIGH
VIEW RECORD
CVE-2026-39453
Product identification pending
Reporter: ICS-CERT
8.5
HIGH
VIEW RECORD
CVE-2026-95702
Product identification pending
Reporter: CVE-COORDINATION
8.5
HIGH
VIEW RECORD
CVE-2026-107815
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-29797
Product identification pending
Reporter: ICS-CERT
8.4
HIGH
VIEW RECORD
CVE-2026-107814
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-107818
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-101947
Product identification pending
Reporter: HELP
8.4
HIGH
VIEW RECORD
CVE-2026-108105
Product identification pending
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-102554
Product identification pending
Reporter: CVE-COORDINATION
8.2
HIGH
VIEW RECORD
CVE-2026-90983
Product identification pending PATCH
Reporter: ILETISIM
8.2
HIGH
VIEW RECORD
CVE-2026-107837
Product identification pending
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-108259
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-22061
Product identification pending
Reporter: SECURITY-ALERT
8.2
HIGH
VIEW RECORD
CVE-2026-94062
Product identification pending
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-94067
Product identification pending
Reporter: AUDIT
8.1
HIGH
VIEW RECORD
CVE-2026-107808
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-107810
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-57458
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-62376
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-104797
Advanced Form Integration — Connect Forms to 300+ Apps
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-104899
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-92975
Groundhogg — CRM, Newsletters, and Marketing Automation
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-94538
WP File Download
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-104759
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-107821
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8
HIGH
VIEW RECORD
CVE-2026-92705
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.8
HIGH
VIEW RECORD
CVE-2026-104629
Product identification pending
Reporter: ICS-CERT
7.7
HIGH
VIEW RECORD
CVE-2026-108101
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108159
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.