Announcements

CVE-2026-44172 (matched: mariadb)

  • 1st August 2026
A security issue has been identified for MariaDB, a popular open-source database software used by many websites to store content and user data. The flaw only impacts MariaDB server versions 3.3.18 and 3.4.8.Under specific conditions, a standard security tool designed to block harmful database commands (known as SQL injection attacks) fails to work ...
Continue reading

CVE-2026-46634 (matched: php)

  • 1st August 2026
A security flaw, tracked as CVE-2026-46634, has been identified in Twig, a popular tool used to build dynamic content for PHP websites. The issue impacts all Twig versions from 3.9.0 up to (but not including) 3.26.0. The flaw lets a template running in a restricted, locked-down security environment (called a sandbox, designed to block risky ...
Continue reading

CVE-2026-15964 (matched: wordpress)

  • 1st August 2026
A security flaw has been found in the Single Sign On For TNG plugin for WordPress, which impacts all versions of the plugin up to and including version 2.0.0. This vulnerability lets people who do not have a login for your site reset the password for any user account on your WordPress site, including administrator accounts. If an attacker exploits ...
Continue reading

CVE-2026-3141 (matched: wordpress)

  • 1st August 2026
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware in routes/rest/api.php. This ...
Continue reading