Announcements

CVE-2026-48907 (matched: php)

  • 24th July 2026
A security vulnerability (identified as CVE-2026-48907) affects the JCE editor extension used on Joomla-based websites. This flaw allows people who do not have valid login credentials for your site to create new, unauthorized editor user profiles for the extension.Once an attacker creates one of these unapproved profiles, they can upload and run ...
Continue reading

CVE-2026-24425 (matched: php)

  • 24th July 2026
A security vulnerability has been identified in Twig, a popular tool used to build dynamic content for many websites. The flaw impacts Twig versions 2.16.x, as well as all versions from 3.9.0 through 3.25.x. This issue is a bypass of Twig's built-in sandbox security feature, which is designed to stop untrusted template code from running harmful ...
Continue reading

CVE-2026-6104 (matched: php)

  • 24th July 2026
A security flaw has been identified in certain recent versions of PHP, the code that powers many dynamic websites. The issue is triggered when a hidden special character (called a NUL byte) is included in a text encoding name passed to common PHP text processing tools. Due to a coding error, PHP miscalculates the length of these inputs, which can ...
Continue reading

CVE-2026-7261 (matched: php)

  • 24th July 2026
A security flaw has been identified in specific older versions of PHP, the core software that powers most dynamic, feature-rich websites. The affected versions are PHP 8.2 releases older than 8.2.31, 8.3 older than 8.3.31, 8.4 older than 8.4.21, and 8.5 older than 8.5.6. The issue only affects sites that use PHP’s SOAP web service tooling ...
Continue reading