FreightCo
by WordPress
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66650 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2026 | Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions. | ||
| CVE-2025-69406 | Hig | 0.53 | 8.1 | 0.01 | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX FreightCo freightco allows PHP Local File Inclusion.This issue affects FreightCo: from n/a through <= 1.1.7. |
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
- risk 0.53cvss 8.1epss 0.01
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX FreightCo freightco allows PHP Local File Inclusion.This issue affects FreightCo: from n/a through <= 1.1.7.