Announcements

CVE-2026-67602 (matched: php)

  • 24th August 2026
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup value alone without including the searched column, enabling an entry written during an app_id lookup to satisfy a ...
Continue reading

CVE-2026-78003 (matched: wordpress)

  • 24th August 2026
A security vulnerability has been identified in the Mailgun for WordPress plugin, affecting all versions up to and including 2.2.0. This flaw allows unauthenticated attackers to send requests to Mailgun's services using your WordPress site's stored Mailgun API key, without needing access to your site or Mailgun account.The most serious risk from ...
Continue reading