Announcements

CVE-2026-78003 (matched: wordpress)

  • 23rd August 2026
A security vulnerability, tracked as CVE-2026-78003, has been found in the Mailgun for WordPress plugin, a tool used to connect WordPress websites to the Mailgun email service. All versions of the plugin up to and including 2.2.0 have a flaw caused by missing proper input checks in the code that manages address lists.This flaw lets unauthenticated ...
Continue reading

TrueConf Server: TrueConf Server Missing Authentication for Critical Function Vulnerability

  • 23rd August 2026
A security vulnerability has been found in TrueConf Server, a tool often used to run video conferencing and team communication services for websites and business operations. The flaw is a missing authentication issue for a critical server function, meaning a key sensitive part of the server does not require valid login credentials to access.If an ...
Continue reading

TrueConf Server: TrueConf Server Code Injection Vulnerability

  • 23rd August 2026
A security flaw has been identified in TrueConf Server. This is a code injection vulnerability, a type of issue that lets unauthorized people run custom, unapproved code on systems running the affected software. To exploit this flaw, an attacker would need network access to port 4307/TCP on the system hosting TrueConf Server. They can send a ...
Continue reading

Synacor Zimbra Collaboration Suite (ZCS): Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

  • 23rd August 2026
A security flaw has been identified in Zimbra Collaboration Suite (ZCS), a software platform many businesses use for team email, shared calendars, and collaborative work tools. The issue is an operating system command injection vulnerability. It allows unauthenticated attackers (people who do not have a login to your Zimbra instance) to send ...
Continue reading