Announcements

CVE-2026-44172 (matched: mariadb)

  • 26th July 2026
A security flaw has been identified in specific older versions of MariaDB, a widely used open-source database system that many websites rely on to store content, user account information, and other site data. The affected versions are 3.3.18 and 3.4.8.This flaw can enable SQL injection attacks, which allow unauthorized users to run unapproved ...
Continue reading

CVE-2026-24425 (matched: php)

  • 26th July 2026
A security flaw has been identified in Twig, a widely used tool for building dynamic PHP websites. The vulnerability impacts Twig versions 2.16.x and 3.9.0 through 3.25.x.When a site uses Twig's sandbox security feature enabled via a source policy (rather than turned on globally for all templates), attackers who have the ability to edit or upload ...
Continue reading

CVE-2026-6104 (matched: php)

  • 26th July 2026
A flaw has been identified in specific versions of PHP, the software that powers most dynamic websites. The issue affects PHP 8.4 releases older than 8.4.21, and PHP 8.5 releases older than 8.5.6. The flaw is in PHP’s mbstring feature, which handles text encoding conversions and detection for website content. If input containing a hidden, ...
Continue reading

CVE-2026-7261 (matched: php)

  • 26th July 2026
A security flaw has been identified in specific older versions of PHP, the software that powers most dynamic websites. The issue only impacts sites that use PHP's SOAP functionality (a tool for communicating with external services) with session persistence enabled, a feature that stores certain session data across user requests to improve ...
Continue reading