Announcements

CVE-2026-65048 (matched: wordpress)

  • 21st July 2026
A security flaw has been found in the Ninja Forms plugin for WordPress, impacting versions 3.10.4 through 3.14.9. The issue is a vulnerability that lets hidden harmful code be saved with form submissions, via the plugin's Repeatable Fieldset feature used to build forms with dynamic, repeatable input sections. This flaw allows anyone, even people ...
Continue reading

CVE-2026-13439 (matched: wordpress)

  • 21st July 2026
A security flaw has been found in the Easy Form Builder by WhiteStudio plugin for WordPress, which affects all versions up to and including 4.0.11. This vulnerability lets people who are not logged into your website gain full administrator access, meaning they could take full control of your site.The flaw exists because the plugin’s password ...
Continue reading

DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • 21st July 2026
A security vulnerability has been identified in DD-WRT, a popular custom firmware installed on many internet routers that customers use to connect their local devices to hosted websites and online services. The flaw takes the form of a stack-based buffer overflow, a type of software memory error that can cause unexpected, harmful behavior.This ...
Continue reading

Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

  • 21st July 2026

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-0770

Continue reading