PT-2025-43325 · Designthemes · Designthemes Knowledge Base

Published

2025-10-22

·

Updated

2025-10-22

·

CVE-2025-60228

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions designthemes Knowledge Base versions prior to 2.9
Description A flaw exists in designthemes Knowledge Base that allows for Object Injection due to deserialization of untrusted data. This issue impacts the application’s ability to securely handle data, potentially leading to unauthorized access or control.
Recommendations Update to a version newer than 2.9.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60228

Affected Products

Designthemes Knowledge Base