A security flaw has been identified in the JCE editor extension, a widely used tool for editing content on Joomla-powered websites. This vulnerability allows anyone without a valid login to your site to create new, unauthorized editor profiles on their own.Once an attacker creates one of these unapproved profiles, they can upload and run custom ...
Continue reading
This security notice is for websites that use Twig, a common template engine for PHP-based sites and web applications that build and display page content.
Certain Twig versions (2.16.x and 3.9.0 through 3.25.x) have a sandbox bypass vulnerability. Twig's sandbox is a built-in safety feature meant to block untrusted code from running when users are ...
Continue reading
A security flaw has been identified in specific versions of PHP, the software that powers most dynamic websites, content management systems, and web applications. The issue affects PHP 8.4 releases older than 8.4.21, and PHP 8.5 releases older than 8.5.6.
The bug triggers when common text encoding functions (used to convert or detect the character ...
Continue reading
A security vulnerability has been identified in specific versions of PHP, the software that powers most dynamic, interactive websites. The affected versions are 8.2 releases older than 8.2.31, 8.3 releases older than 8.3.31, 8.4 releases older than 8.4.21, and 8.5 releases older than 8.5.6.The flaw occurs when a specific PHP feature called ...
Continue reading