A critical security vulnerability, tracked as CVE-2026-39932, has been identified in OpenEMR, an open-source electronic medical records platform, affecting all versions up to 8.2.0. The flaw exists in the software’s document category management feature, and allows someone who already has administrator-level access to the OpenEMR system to run ...
Continue reading
A security flaw has been found in specific versions of PHP, the software that powers many interactive, dynamic websites. The issue impacts PHP 8.4 releases older than 8.4.24, and PHP 8.5 releases older than 8.5.9.The flaw is triggered when an attacker sends specially crafted input to the bccomp() function on a site running an affected PHP version. ...
Continue reading
A security flaw has been found in specific versions of PHP, the common software that powers interactive features on many websites, including contact forms, user login systems, and content management tools. The issue stems from improper handling of backslashes in inputs provided by website visitors, such as form submissions or URL parameters.If ...
Continue reading
A security vulnerability has been identified in the Aimy Captcha-Less Form Guard extension for Joomla, versions 18.0 to 20.0, sold by aimy-extensions.com. The flaw allows bad actors to send a specially crafted value in the form's "clfgd" field to inject harmful PHP code into your website, which lets them run unauthorized remote commands on your ...
Continue reading