A security flaw has been identified in Apache HTTP Server, the software that runs many websites online. The issue affects a component that passes visitor requests to backend servers: a specially crafted web request can trick this component into sending the request to a server controlled by an attacker, rather than your intended backend ...
Continue reading
A security flaw has been found in MariaDB, a widely used open-source database system for websites, affecting versions 3.3.18 and 3.4.8.
The issue impacts sites that accept unvalidated user input, use the big5 character set, and send that input to the database via text protocol. Even when sites used the standard mysql_real_escape_string() tool, ...
Continue reading
A security vulnerability tracked as CVE-2026-8457 affects the WooCommerce Social Login plugin for WordPress, impacting all versions up to and including 2.8.7. The flaw exists in how the plugin processes Apple logins: it does not validate that login tokens from Apple are legitimate, and a required security check for starting the login flow is ...
Continue reading
A security flaw has been found in the Single Sign On For TNG plugin for WordPress. All versions of this plugin up to and including version 2.0.0 have an authentication bypass vulnerability, meaning anyone who visits your website (even if they are not logged into your WordPress dashboard) can reset the password for any account on the site, ...
Continue reading