Announcements

CVE-2026-48907 (matched: php)

  • 23rd July 2026
A security vulnerability has been found in the JCE Editor extension, an add-on for Joomla, a popular tool for building and managing websites. The flaw lets people who do not have an account or login for your Joomla site create their own editor profiles for the JCE extension. This access allows them to upload and run PHP code on your website. Being ...
Continue reading

CVE-2026-48687 (matched: php)

  • 23rd July 2026
A security flaw has been identified in FastNetMon Community Edition, up to and including version 1.2.9, specifically in its Juniper router integration feature. This is a command injection vulnerability: the tool’s logging function takes input from external command lines and inserts it directly into system commands without checking for malicious ...
Continue reading

CVE-2026-24425 (matched: php)

  • 23rd July 2026
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass ...
Continue reading

CVE-2026-6722 (matched: php)

  • 23rd July 2026
PHP is the core software that powers most dynamic websites and web applications, including content management systems, e-commerce stores, and custom web tools. A security flaw has been identified in specific, unpatched versions of PHP: 8.2 releases older than 8.2.31, 8.3 releases older than 8.3.31, 8.4 releases older than 8.4.21, and 8.5 releases ...
Continue reading