Announcements

CVE-2026-39932 (matched: php)

  • 5th August 2026
A critical security flaw has been found in OpenEMR, a popular open-source electronic medical records platform, affecting all versions up to 8.2.0. The flaw exists in the software's document category organization feature, which is used to sort and manage stored files and records.The vulnerability allows users with full administrator access to the ...
Continue reading

CVE-2026-5581 (matched: wordpress)

  • 5th August 2026
A security flaw has been found in the Multi Uploader for Gravity Forms plugin for WordPress, affecting all versions up to and including 1.1.8. This issue lets people who do not have login access to your WordPress site permanently delete any media files you have uploaded to your site, such as product images, blog photos, videos, or documents.The ...
Continue reading

CVE-2026-4431 (matched: wordpress)

  • 5th August 2026
A security vulnerability has been identified in the Easy Post Submission plugin for WordPress, a tool many site owners use to let visitors submit content to their websites. The flaw impacts all versions of the plugin up to and including version 2.3.0.The issue is caused by a missing permission check on a core plugin feature that was supposed to ...
Continue reading

CVE-2026-9273 (matched: wordpress)

  • 5th August 2026
A security vulnerability has been found in the Kadence Memberships (previously called Restrict Content) plugin for WordPress, which affects all versions up to 4.0.0. This plugin is used to manage access to members-only content and features on WordPress websites.The flaw lets unauthenticated bad actors manipulate the plugin's password reset feature ...
Continue reading