IOFactory::load. Executing a manipulation of the argument filename can lead to deserialization.
This vulnerability is tracked as CVE-2026-34084. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
Intelligence View
SOCIAL SHARE CARD GENERATOR