Announcements

CVE-2026-4703 (matched: wordpress)

  • 23rd August 2026
A security issue tracked as CVE-2026-4703 affects the free WS Form LITE drag-and-drop contact form builder plugin for WordPress. All versions of the plugin up to and including version 1.10.80 have this flaw.The issue exists because the plugin does not safely handle data submitted through the contact forms it creates. This allows attackers who do ...
Continue reading

CVE-2026-78003 (matched: wordpress)

  • 23rd August 2026
A security vulnerability has been found in the Mailgun for WordPress plugin, impacting all versions up to and including 2.2.0. The flaw is a server-side request forgery (SSRF) issue caused by insufficient input validation when the plugin processes address data submitted via forms on your WordPress site.Unauthenticated attackers can exploit this ...
Continue reading

TrueConf Server: TrueConf Server Missing Authentication for Critical Function Vulnerability

  • 23rd August 2026
A security vulnerability has been found in TrueConf Server, a service some hosting clients may run for their websites or business tools. The flaw affects a critical server function that does not require proper user authentication, meaning no valid login credentials are needed to access it.An unauthorized attacker who can connect to the server over ...
Continue reading

TrueConf Server: TrueConf Server Code Injection Vulnerability

  • 23rd August 2026
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.Source: CISA Known Exploited Vulnerabilities Catalog — ...
Continue reading