Announcements

CVE-2026-4703 (matched: php)

  • 22nd August 2026
A security flaw has been found in the WS Form LITE drag-and-drop contact form builder plugin for WordPress, a tool used to create custom contact forms on websites. The flaw impacts all versions of the plugin up to and including 1.10.80, and allows people who do not have login access to your site to inject harmful code objects through data ...
Continue reading

CVE-2026-4703 (matched: wordpress)

  • 22nd August 2026
A security vulnerability has been found in the WS Form LITE drag-and-drop contact form builder plugin for WordPress, impacting all versions up to 1.10.80. The flaw allows unauthenticated visitors to your site (people who do not have a login for your WordPress dashboard) to send malicious input through form submissions that can inject harmful code ...
Continue reading

CVE-2026-78003 (matched: wordpress)

  • 22nd August 2026
A security vulnerability has been found in the Mailgun for WordPress plugin, impacting all versions of the tool up to and including 2.2.0. The flaw exists because the plugin does not properly validate user-provided input when processing address lists, allowing unauthenticated attackers to send forged, authorized requests to Mailgun's services ...
Continue reading

MLflow MLflow: MLflow Server-Side Request Forgery Vulnerability

  • 22nd August 2026
A security flaw called server-side request forgery (SSRF) has been found in MLflow, a tool many website owners use to manage machine learning projects on their hosting servers.If you use MLflow for your work, this vulnerability could let bad actors send requests from your MLflow setup to internal network services or cloud metadata services that ...
Continue reading