Announcements

CVE-2026-78570 (matched: wordpress)

  • 25th August 2026
A security flaw has been found in the Total Donations plugin for WordPress, a tool many sites use to manage donation campaigns. All versions of this plugin up to and including version 2.0.5 are affected by a privilege escalation issue, which means people who do not have a valid login account for your site can gain full administrator-level access ...
Continue reading

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

  • 25th August 2026
A security flaw has been identified in the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, tools used to manage traffic routing for web applications running on these server systems. The issue is an improper access control vulnerability, which means unauthorized users could potentially gain entry to parts of the system they are not ...
Continue reading

Gitea Gitea: Gitea Code Injection Vulnerability

  • 25th August 2026
A security vulnerability has been identified in Gitea, the open-source code repository management tool used by some of our hosting clients to store and manage project code. This is a code injection flaw that impacts Gitea instances.To exploit the flaw, an attacker who already has write access to a Gitea repository can send a specially crafted ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 25th August 2026
On July 20, 2026, cybersecurity authority MyCERT released security advisory MA-1471.072026 for Microsoft SharePoint, following confirmation of new active exploits targeting the platform. SharePoint is a widely used tool for organizations to host, share, and collaborate on content, including for public-facing website sections and internal ...
Continue reading