Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.
CVE-2026-94683 at the National Vulnerability Database