Announcements

CVE-2026-8711 (matched: nginx)

  • 25th July 2026
A vulnerability has been identified in NGINX JavaScript that only impacts sites with specific configuration settings. The flaw affects setups where the js_fetch_proxy directive is set to use at least one NGINX variable that pulls data from user input (such as HTTP headers, URL parameters, or cookies) and also calls the ngx.fetch() function from ...
Continue reading

CVE-2026-44172 (matched: mariadb)

  • 25th July 2026
A security flaw has been identified in two specific versions of MariaDB, a popular open-source database software used by many websites to store data such as user information, site content, and order records. The affected versions are 3.3.18 and 3.4.8.Normally, developers use a standard tool called mysql_real_escape_string() to block SQL injection ...
Continue reading

CVE-2026-48907 (matched: php)

  • 25th July 2026
A security flaw has been identified in the JCE editor extension, a widely used tool for editing content on Joomla-powered websites. This vulnerability allows anyone without a valid login to your site to create new, unauthorized editor profiles on their own.Once an attacker creates one of these unapproved profiles, they can upload and run custom ...
Continue reading

CVE-2026-24425 (matched: php)

  • 25th July 2026
This security notice is for websites that use Twig, a common template engine for PHP-based sites and web applications that build and display page content. Certain Twig versions (2.16.x and 3.9.0 through 3.25.x) have a sandbox bypass vulnerability. Twig's sandbox is a built-in safety feature meant to block untrusted code from running when users are ...
Continue reading