A security flaw has been found in the Aimy Captcha-Less Form Guard extension for Joomla, versions 18.0 through 20.0, made by aimy-extensions.com.The vulnerability works when an attacker sends a specially crafted request using a form field named clfgd. This lets them inject malicious code into your site’s PHP systems, which can then run ...
Continue reading
A security flaw has been found in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress, a tool used to manage appointment bookings on websites. The issue impacts every version of the plugin up to and including version 1.2.3, and occurs because the plugin does not properly check if a person trying to make changes is ...
Continue reading
A security flaw has been found in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress. The issue impacts all versions of the plugin up to and including version 1.2.3, and stems from the plugin failing to properly verify a person’s identity before processing a password reset request.This vulnerability allows ...
Continue reading
A security vulnerability has been identified in IBM Langflow, a low-code application building tool that some users host on our platforms. The flaw is a code injection issue, which allows outside actors to run unauthorized, harmful code on the server where Langflow is installed.This vulnerability is especially serious because attackers do not need ...
Continue reading