PT-2026-23248 · Boldthemes · Celeste

João Pedro S Alcântara

+1

·

Published

2026-03-05

·

Updated

2026-03-05

·

CVE-2026-27369

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BoldThemes Celeste versions through 1.3.6
Description A flaw exists in BoldThemes Celeste that allows for object injection due to deserialization of untrusted data. This issue could potentially allow an attacker to compromise the system.
Recommendations Update BoldThemes Celeste to a version later than 1.3.6.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-27369

Affected Products

Celeste