Announcements

CVE-2026-46420 (matched: php)

  • 18th August 2026
A security flaw has been identified in setup-php, a common tool used to configure PHP for automated project workflows run on GitHub's Actions system. The flaw impacts all versions of the tool from 2.25.0 up to (but not including) 2.37.1.This tool pulls PHP version details from files stored in a project's code repository, including .php-version, ...
Continue reading

CVE-2019-11049 (matched: php)

  • 18th August 2026
A security flaw has been found in specific versions of PHP, the software that powers many websites, when it runs on Windows servers. The issue affects PHP 7.3.x versions older than 7.3.13, as well as PHP 7.4.0. It is triggered when your website uses PHP’s built-in mail() function to send emails with custom headers written in lowercase, and is ...
Continue reading

CVE-2026-15748 (matched: wordpress)

  • 18th August 2026
A security vulnerability has been found in the Forminator Forms plugin for WordPress, a tool used to add forms and file upload features to WordPress websites. The flaw impacts every version of the plugin up to and including version 1.56.1. This issue lets people who do not have an account or login access to your site upload dangerous files that ...
Continue reading

CVE-2026-18432 (matched: wordpress)

  • 18th August 2026
A security flaw has been found in the Frontend Admin by DynamiApps plugin for WordPress, affecting all versions up to and including 3.29.9. This is a privilege escalation vulnerability, meaning it lets unauthorized people gain higher-level access to your WordPress site than they are supposed to have. Attackers can exploit this issue without being ...
Continue reading