Announcements

CVE-2026-48907 (matched: php)

  • 25th July 2026
A security flaw, identified as CVE-2026-48907, exists in the JCE editor extension used by Joomla websites. This vulnerability allows people who do not have an account or login credentials for your Joomla site to create new editor profiles on the platform. Once created, these profiles let attackers upload and run harmful PHP code directly on your ...
Continue reading

CVE-2026-24425 (matched: php)

  • 25th July 2026
A security vulnerability has been found in Twig, a common tool used to build and render dynamic website templates. The flaw affects Twig versions 2.16.x, as well as all releases from 3.9.0 up to 3.25.x.The issue lets attackers bypass Twig’s built-in template sandbox, a security feature meant to restrict what code templates are allowed to run. ...
Continue reading

CVE-2026-6104 (matched: php)

  • 25th July 2026
A security issue has been identified in specific versions of PHP, the software that powers most dynamic, interactive websites. It affects PHP 8.4 releases older than 8.4.21, and PHP 8.5 releases older than 8.5.6.The flaw is triggered when a specially crafted encoding name with a hidden, embedded null character is passed to common PHP text handling ...
Continue reading

CVE-2026-7261 (matched: php)

  • 25th July 2026
A security flaw, tracked as CVE-2026-7261, has been found in specific older versions of PHP, the software that powers many websites. The issue only impacts sites that use PHP's SOAP feature (a tool for connecting different web services to each other) and have that feature set to save user session data across requests. The affected PHP versions are ...
Continue reading