PT-2026-23352 · Themerex · Pizza House

Tran Nguyen Bao Khanh

·

Published

2026-03-05

·

Updated

2026-03-05

·

CVE-2026-28074

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ThemeREX Pizza House versions through 1.4.0
Description A flaw exists in ThemeREX Pizza House that allows for object injection due to deserialization of untrusted data. This issue could potentially allow an attacker to compromise the system.
Recommendations Update ThemeREX Pizza House to a version newer than 1.4.0.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-28074

Affected Products

Pizza House