Announcements

CVE-2021-40438 (matched: apache http server)

  • 2nd August 2026
A security issue has been identified in Apache HTTP Server, the common software used to run and manage websites. This flaw affects Apache HTTP Server version 2.4.48 and all earlier released versions of the software.The issue impacts the server's mod_proxy feature, which passes incoming visitor requests to backend systems that power the site. If a ...
Continue reading

CVE-2026-8457 (matched: wordpress)

  • 2nd August 2026
A security flaw has been found in the WooCommerce Social Login plugin for WordPress, affecting all versions up to and including 2.8.7. The issue is in the plugin's Apple login feature: it fails to properly verify that login tokens from Apple are legitimate, and a security code meant to protect the login process is publicly visible to anyone who ...
Continue reading

CVE-2026-15964 (matched: wordpress)

  • 2nd August 2026
A security vulnerability has been identified in the Single Sign On For TNG plugin for WordPress, impacting all versions up to and including 2.0.0. This flaw allows anyone who visits your website, even without a login or user account, to reset the password for any user on your WordPress site, including administrator accounts. The issue exists ...
Continue reading

CVE-2026-3141 (matched: wordpress)

  • 2nd August 2026
A security flaw has been found in the FormGent plugin for WordPress, impacting all versions up to and including 1.9.2. The issue comes from a missing authentication check on a specific plugin API endpoint, which lets unauthenticated attackers (people who do not have valid login credentials for your website) delete files stored in the FormGent ...
Continue reading