Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2614+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
110 articles

#Web Security

All CosmicBytez Labs articles tagged #Web Security, across news, security advisories, how-to guides, and projects.

  • SecurityAug 31, 2026

    CVE-2026-82610: SQL Injection in itsourcecode Online Medicine Delivery System

    An unauthenticated SQL injection in the employee login of itsourcecode's Online Medicine Delivery System 1.0 has a public exploit available.

  • SecurityAug 30, 2026

    Sigma Forms Pro WordPress Plugin: Unauthenticated RCE via File Upload (CVE-2026-14494)

    CVE-2026-14494 (CVSS 9.8) lets unauthenticated attackers upload PHP webshells through Sigma Forms Pro's default form templates. No patch yet.

  • SecurityAug 28, 2026

    CVE-2026-32479: Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro

    Critical unauthenticated SQL injection (CVSS 9.3) in the WordPress plugin Visitor Traffic Real Time Statistics Pro ≤ 11.17. Patch to 11.18.

  • SecurityAug 28, 2026

    CVE-2026-32566: Unauthenticated Privilege Escalation in ACPT (Pro) Custom Post Types Plugin

    Critical unauthenticated privilege escalation (CVSS 9.8) in WordPress plugin ACPT (Pro) ≤ 2.0.63. No official patch yet — Patchstack has a mitigation rule.

  • SecurityAug 26, 2026

    Critical TranslatePress Flaw Exposes 400,000+ WordPress Sites to Account Takeover

    CVE-2026-19632 leaks a plaintext admin password-reset key via an unauthenticated AJAX action in TranslatePress, enabling full site takeover.

  • SecurityAug 24, 2026

    CVE-2026-7808: justhtml HTML Sanitization Bypass (Critical XSS)

    Critical XSS in justhtml before 1.16.0. Multiple bypass paths let dangerous content survive sanitization, enabling script injection with no auth required.

  • SecurityAug 24, 2026

    CVE-2026-78143: SQL Injection in Barangay Resident Profiling Management System

    High-severity SQL injection in Barangay Resident Profiling System 1.0 lets remote attackers extract personal data via the residents.php Search parameter.

  • SecurityAug 23, 2026

    CVE-2026-5388: Critical XSS Sanitization Bypass in justhtml

    justhtml before 1.15.0 has multiple sanitization failures allowing XSS bypass via URL helpers, HTML serialization, and Markdown passthrough.

  • NewsAug 20, 2026

    Critical Elementor Pro Bug Exposes WordPress Sites to RCE Attacks

    CVE-2026-32475 (CVSS 9.0): Unauthenticated attackers can upload PHP webshells via a loop desync flaw in Elementor Pro's file upload field.

  • SecurityAug 20, 2026

    CVE-2026-53545: Termix SSH Tunnel Command Injection — CVSS 9.8 Critical

    Critical OS command injection in Termix's SSH tunnel teardown lets authenticated attackers execute arbitrary OS commands on hosts. Patch to 2.3.2.

  • SecurityAug 20, 2026

    Critical Unauthenticated RCE in JetEngine WordPress Plugin (CVE-2026-66613)

    A CVSS 9.8 unauthenticated remote code execution flaw in JetEngine plugin <= 3.8.14 lets attackers fully compromise WordPress sites.

  • SecurityAug 20, 2026

    Critical SQL Injection in Maps Marker Pro WordPress Plugin (CVE-2026-73183)

    An unauthenticated SQL injection flaw (CVSS 9.3) in Maps Marker Pro <= 4.32 exposes WordPress databases to full read and write access.

  • SecurityAug 18, 2026

    CVE-2026-55674: Discourse Unauthenticated HTML Injection via Cookie

    A CVSS 9.3 critical flaw in Discourse allows unauthenticated attackers to inject arbitrary HTML using a crafted cookie value.

  • SecurityAug 18, 2026

    CVE-2026-74800: SiYuan Stored XSS via Asset Upload Enables Full Kernel API Access

    SiYuan before 3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers, enabling stored XSS with full kernel API access.

  • SecurityAug 16, 2026

    CVE-2026-14498: Query Wrangler WordPress Plugin Exposes Sites to RCE

    A high-severity RCE flaw (CVSS 8.8) in the Query Wrangler WordPress plugin lets authenticated attackers inject and execute arbitrary PHP via a missing capability check.

  • SecurityAug 16, 2026

    CVE-2026-14524: Critical Unauthenticated File Deletion in ProSolution WP Client

    A CVSS 9.1 flaw in ProSolution WP Client lets unauthenticated attackers delete arbitrary files on WordPress servers, potentially wiping installations.

  • SecurityAug 16, 2026

    CVE-2026-15002: Stored XSS in Autopay WooCommerce Plugin for WordPress

    CVE-2026-15002 is a stored XSS flaw (CVSS 7.2) in the Autopay WooCommerce plugin, letting attackers inject persistent scripts via the CSS editor POST parameter.

  • SecurityAug 16, 2026

    CVE-2026-15142: Real Estate Manager Pro Privilege Escalation via Capability Confusion

    CVSS 7.5 flaw in Real Estate Manager Pro for WordPress lets attackers escalate privileges by exploiting an attachment ID and user ID confusion bug.

  • SecurityAug 16, 2026

    CVE-2026-16142: TrueBooker WordPress Plugin Unauthenticated Account Takeover

    A CVSS 9.8 flaw in TrueBooker for WordPress allows unauthenticated attackers to take over any user account via a vulnerable AJAX handler.

  • SecurityAug 16, 2026

    CVE-2026-18438: Templately WordPress Plugin RCE via File Upload

    CVSS 8.8 flaw in Templately for WordPress lets authenticated subscribers execute arbitrary code via a filename validation bypass in file upload.

  • SecurityAug 13, 2026

    CVE-2026-14182: WooCommerce Email Verification Bypass Allows Account Takeover

    A CVSS 9.8 type juggling flaw in Customer Email Verification for WooCommerce lets unauthenticated attackers take over any customer account.

  • SecurityAug 11, 2026

    CVE-2026-19425: Critical SQL Injection in Travel Agency Management System

    A critical unauthenticated SQL injection vulnerability in Win Men International's Travel Agency Management System allows remote attackers to read, modify, and delete all database contents without any credentials.

  • NewsAug 8, 2026

    New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

    PortSwigger researcher Gareth Heyes demonstrated at Black Hat USA 2026 that CSS and HTML within emails can escape message boundaries to capture typed passwords, steal session tokens, and leak IP addresses across Outlook, Gmail, Yahoo, Proton Mail, Fastmail, and AOL Mail.

  • SecurityAug 8, 2026

    CVE-2026-19264: Critical Path Traversal in Postiz Exposes JWT Secrets and DB Credentials

    A critical unauthenticated path traversal vulnerability in Postiz, the open-source social media scheduling platform, allows attackers to read arbitrary files including JWT secrets, database credentials, and API tokens — enabling full admin takeover.

  • SecurityAug 6, 2026

    CVE-2026-12713: Critical SQL Injection in WPCargo Track & Trace Plugin

    An unauthenticated SQL injection vulnerability (CVSS 9.1) in the WPCargo Track & Trace WordPress plugin before version 8.0.4 allows attackers to read and manipulate database contents without any credentials.

  • NewsAug 1, 2026

    Ruby on Rails Patches Critical Vulnerability Enabling File Read and RCE

    The Ruby on Rails team has released an emergency patch for a critical security flaw that allows unauthenticated attackers to read arbitrary files and potentially achieve remote code execution on vulnerable applications.

  • SecurityJul 31, 2026

    CVE-2025-65336: Critical SQL Injection in Fruits Bazar PHP Ecommerce

    CVSS 9.8 SQL injection vulnerability in the show_price_by_pdtId.php endpoint of the Fruits Bazar PHP/MySQLi ecommerce project allows unauthenticated attackers to read and manipulate the entire database.

  • SecurityJul 31, 2026

    CVE-2025-69941: Critical SQL Injection in Tailor Management System — Measurement Endpoint

    CVSS 9.8 SQL injection in SourceCodester Tailor Management System 1.0 allows unauthenticated attackers to read, modify, or delete all database records through the addmeasurement.php endpoint.

  • SecurityJul 31, 2026

    CVE-2025-69947: Critical SQL Injection in Tailor Management System — Customer Edit Endpoint

    CVSS 9.8 SQL injection in SourceCodester Tailor Management System 1.0 exposes full customer records through an unsanitized id parameter in customeredit.php, enabling unauthenticated data exfiltration.

  • SecurityJul 31, 2026

    CVE-2026-15397: Missing Authorization in Subscriptions for WooCommerce Plugin

    A missing authorization vulnerability in the Subscriptions for WooCommerce plugin allows authenticated users with minimal privileges to perform unauthorized actions on WordPress sites running versions up to 2.0.0.

  • SecurityJul 28, 2026

    CVE-2026-14545: TrueBooker WordPress Plugin Lets Anyone Take Over Admin Accounts

    An unauthenticated password reset flaw in TrueBooker (before v1.2.4) lets any attacker set an arbitrary password on any WordPress account — including administrators — and take full control of the site.

  • SecurityJul 28, 2026

    CVE-2026-59527: Critical SQL Injection in MapSVG WordPress Plugin

    A CVSS 9.3-rated unauthenticated SQL injection vulnerability in the MapSVG WordPress plugin (versions up to 8.14.0) allows remote attackers to read and manipulate the underlying database without any login credentials.

  • NewsJul 27, 2026

    'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

    Attackers are actively chaining CVE-2026-60137 and CVE-2026-63030 just three days after disclosure, targeting one of the largest attack surfaces on the internet.

  • SecurityJul 27, 2026

    CVE-2026-12394: MemberGlut Plugin Lets Anyone Register as WordPress Admin

    A critical privilege escalation flaw in the MemberGlut WordPress plugin allows unauthenticated users to register with any role — including administrator — leading to full site compromise.

  • SecurityJul 27, 2026

    CVE-2026-13597: WeChat QR Login WordPress Plugin Authentication Bypass

    A critical authentication bypass in the WeChat QR login WordPress plugin allows unauthenticated attackers to forge login events for any account — the webhook signature check always passes and login codes are leaked in responses.

  • SecurityJul 27, 2026

    CVE-2026-14289: FacturaONE WooCommerce Plugin Allows Unauthenticated File Write

    A critical unauthenticated arbitrary file write vulnerability in the FacturaONE para WooCommerce con VeriFactu plugin (before v5.37) allows attackers to write arbitrary files due to an empty cryptographic key in the default unconfigured state.

  • SecurityJul 26, 2026

    CVE-2026-15962: PHP Object Injection in Fluent Forms Pro (CVSS 8.8)

    A high-severity PHP Object Injection vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress allows authenticated attackers with Subscriber-level access to inject PHP objects and potentially achieve remote code execution via a POP chain in versions up to 6.2.6.

  • SecurityJul 24, 2026

    CVE-2026-12877: Critical SQL Injection in WordPress Project Management Plugin

    An unauthenticated SQL injection flaw with a CVSS score of 9.1 affects the Project Management, Bug and Issue Tracking Plugin for WordPress before version...

  • SecurityJul 22, 2026

    CVE-2026-62415: Joomla Membership Pro Allows Unauthenticated File Upload

    The Joomla extension Membership Pro prior to version 4.6.2 allowed unauthenticated users to upload media assets by default, exposing sites to potential...

  • SecurityJul 22, 2026

    CVE-2026-65048: Ninja Forms Unauthenticated Stored XSS via Repeatable Fieldset

    A CVSS 9.3 critical stored XSS vulnerability in the Ninja Forms WordPress plugin affects versions 3.10.4 through 3.14.9. The flaw requires no...

  • SecurityJul 22, 2026

    CVE-2026-65049: Ninja Forms Multisite Flaw Enables Network-Wide Data Deletion

    A CVSS 9.3 critical incorrect authorization vulnerability in Ninja Forms 3.14.8 and prior for WordPress Multisite allows a subsite administrator to...

  • NewsJul 21, 2026

    WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

    Attackers are exploiting two chained critical WordPress vulnerabilities that enable unauthenticated remote code execution. A public exploit has triggered...

  • SecurityJul 21, 2026

    CVE-2026-13439: WordPress Easy Form Builder Unauthenticated Privilege Escalation (CVSS 9.8)

    A critical unauthenticated privilege escalation vulnerability in the Easy Form Builder by WhiteStudio WordPress plugin allows attackers to reset admin...

  • SecurityJul 20, 2026

    CVE-2026-10081: Unlimited Elements for Elementor Stored XSS via Google Reviews

    A stored cross-site scripting vulnerability in the Unlimited Elements for Elementor WordPress plugin (before 2.0.11) allows unauthenticated attackers to...

  • SecurityJul 20, 2026

    CVE-2026-13147: Kirki WordPress Plugin SSRF Allows Unauthenticated Internal Network Scanning

    A server-side request forgery vulnerability in the Kirki Customizer Framework WordPress plugin before 6.0.12 allows unauthenticated attackers to make the...

  • HOWTOJul 20, 2026

    Nginx + ModSecurity WAF: Protecting Web Apps with OWASP CRS

    Deploy ModSecurity v3 as an Nginx module, wire in the OWASP Core Rule Set, tune false positives, and verify SQL injection and XSS are blocked — all on a...

  • SecurityJul 19, 2026

    CVE-2026-16152: SQL Injection in SourceCodester Class and Exam Timetabling System

    A remotely exploitable SQL injection vulnerability has been disclosed in SourceCodester Class and Exam Timetabling System 1.0. The flaw in /edit_rooma.php...

  • SecurityJul 19, 2026

    CVE-2026-16154: SQL Injection in SourceCodester Timetabling Room Management

    A second SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 has been disclosed, this time affecting the /edit_room1.php...

  • NewsJul 13, 2026

    CISA Warns of Actively Exploited RCE Flaws in Joomla Extensions

    CISA has added two Joomla extension vulnerabilities to its KEV catalog after attackers began exploiting arbitrary file upload flaws in iCagenda and...

  • NewsJul 13, 2026

    iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days

    CISA has added two maximum-severity flaws in iCagenda and Balbooa Forms Joomla extensions to its KEV catalog following confirmed zero-day exploitation in...

  • SecurityJul 12, 2026

    CVE-2026-15489: SQL Injection in TOKO-ONLINE-ROTI Login Endpoint

    A high-severity SQL injection vulnerability in the TOKO-ONLINE-ROTI bakery management system allows remote attackers to manipulate the login.php Username...

  • SecurityJul 12, 2026

    CVE-2026-15490: SQL Injection in TOKO-ONLINE-ROTI Product Add Endpoint

    A high-severity SQL injection vulnerability in the TOKO-ONLINE-ROTI PHP bakery system allows remote attackers to manipulate the kode_produk and kd_cs...

  • NewsJul 11, 2026

    Australia Warns of Global Campaign Targeting Vulnerable CMS Platforms

    The Australian Cyber Security Centre has issued an alert about a coordinated global campaign actively exploiting unpatched vulnerabilities in WordPress,...

  • SecurityJul 8, 2026

    CVE-2026-48908: JoomShaper SP Page Builder Unrestricted File Upload RCE

    A critical unrestricted file upload vulnerability in JoomShaper's SP Page Builder allows unauthenticated attackers to upload arbitrary PHP files and...

  • SecurityJul 6, 2026

    CVE-2026-14732: SQL Injection in SourceCodester Timetabling System via /edit_exam.php

    A high-severity SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows remote attackers to manipulate the database via...

  • SecurityJul 6, 2026

    CVE-2026-14733: SQL Injection in SourceCodester Timetabling System via /edit_coursea.php

    A high-severity SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows remote attackers to manipulate the database via...

  • SecurityJul 6, 2026

    CVE-2026-14734: SQL Injection in SourceCodester Timetabling System via /edit_product.php

    A high-severity SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows remote attackers to manipulate the database via...

  • SecurityJul 5, 2026

    CVE-2026-14652: SQL Injection in SourceCodester Shopping Cart Admin Login

    A high-severity SQL injection vulnerability in SourceCodester Simple and Nice Shopping Cart Script 1.0 allows remote attackers to manipulate the admin...

  • SecurityJul 5, 2026

    CVE-2026-14653: SQL Injection in Shopping Cart Men's Product Delete Endpoint

    A high-severity SQL injection flaw in SourceCodester Simple and Nice Shopping Cart Script 1.0 exposes the men's product delete query to remote...

  • SecurityJul 5, 2026

    CVE-2026-14654: SQL Injection in Shopping Cart Girls Product Delete Endpoint

    A high-severity SQL injection vulnerability in SourceCodester Simple and Nice Shopping Cart Script 1.0 allows remote attackers to exploit the girls...

  • SecurityJul 5, 2026

    CVE-2026-14688: SQL Injection in itsourcecode Hotel Management Admin Login

    A high-severity SQL injection vulnerability in itsourcecode Online Hotel Management System 1.0 allows remote attackers to exploit the admin login page via...

  • SecurityJul 5, 2026

    SQL Injection in Multi-Vendor Online Grocery Management System (CVE-2026-14695)

    A high-severity SQL injection vulnerability in SourceCodester's Multi-Vendor Online Grocery Management System 1.0 allows remote attackers to manipulate...

  • SecurityJul 5, 2026

    SQL Injection in Pizzafy E-Commerce System Exposes Order Data (CVE-2026-14713)

    A remotely exploitable SQL injection flaw in SourceCodester Pizzafy E-Commerce System 1.0 allows attackers to manipulate the confirm_order endpoint via an...

  • SecurityJul 5, 2026

    Privilege Escalation via Role Manipulation in Online Exam LMS (CVE-2026-14719)

    A high-severity improper privilege management flaw in SourceCodester's Online Examination and Learning Management System 1.0 allows remote attackers to...

  • SecurityJul 4, 2026

    CVE-2026-14622: Missing Authentication in Restaurant Website PHP/MySQL AJAX Endpoint

    A missing authentication vulnerability (CVSS 7.3) in the jairiidriss/restaurant-website-php-mysql project exposes the /admin/ajax_files endpoint to...

  • SecurityJun 28, 2026

    CVE-2026-13487: SQL Injection in SourceCodester Timetabling System (/archive.php)

    A high-severity SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows unauthenticated attackers to manipulate the...

  • SecurityJun 28, 2026

    CVE-2026-13488: SQL Injection in SourceCodester Timetabling System (/preview7.php)

    A high-severity SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows unauthenticated attackers to manipulate the...

  • SecurityJun 28, 2026

    CVE-2026-13498: SQL Injection in Restaurant Management System via Password Reset

    A high-severity SQL injection vulnerability in yashpokharna2555's restaurant management system allows unauthenticated attackers to exploit the...

  • NewsJun 21, 2026

    Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

    Active exploitation of CVE-2026-4020 in the Gravity SMTP WordPress plugin has generated over 17 million malicious requests, allowing unauthenticated...

  • SecurityJun 10, 2026

    CVE-2009-10007: Catalyst::Plugin::Authentication Session Fixation

    CVSS 9.1 session fixation flaw in Perl's Catalyst auth plugin (before 0.10_027) lets attackers impersonate authenticated users by pre-planting a known...

  • NewsJun 6, 2026

    Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites

    Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin, enabling them to take complete control of…

  • NewsJun 6, 2026

    Suspicious Polyfill Login Prompts Pop Up on Toshiba, Muji Websites

    Tech giant Toshiba and mega-retailer Muji have warned visitors that suspicious sign-in screens appearing on their websites could be harvesting credentials — a…

  • SecurityJun 4, 2026

    CVE-2026-49191: M3WebServer Hard-Coded API Keys Exposed via Error Pages

    A critical CVSS 9.8 vulnerability in M3WebServer hard-codes backend API keys in the production build. Attackers intercept them through verbose error handling…

  • NewsJun 3, 2026

    Critical Kirki Flaw Exploited to Hijack WordPress Admin Accounts

    Hackers are actively exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the widely-used Kirki Customizer Framework plugin for…

  • NewsMay 31, 2026

    WP Maps Pro Bug Exploited to Create Admin Accounts on WordPress Sites

    Hackers are actively exploiting a critical vulnerability in the WP Maps Pro WordPress plugin that allows unauthenticated attackers to create rogue…

  • SecurityMay 31, 2026

    CVE-2018-25405: Multiple SQL Injections in eNdonesia Portal 8.7

    Multiple unauthenticated SQL injection vulnerabilities in eNdonesia Portal 8.7 allow attackers to extract sensitive database contents via the artid, cid,...

  • SecurityMay 31, 2026

    CVE-2018-25406: SQL Injection Across eNdonesia Portal 8.7 Modules

    Multiple unauthenticated SQL injection vulnerabilities in eNdonesia Portal 8.7 expose the publisher, artikel, and info modules to database extraction...

  • SecurityMay 31, 2026

    CVE-2018-25411: SQL Injection in MGB OpenSource Guestbook 0.7.0.2

    An unauthenticated SQL injection vulnerability in MGB OpenSource Guestbook 0.7.0.2 allows attackers to extract sensitive database contents via the 'id'...

  • SecurityMay 31, 2026

    CVE-2018-25412: Arbitrary File Upload RCE in Delta Sql 1.8.2

    A critical unauthenticated arbitrary file upload vulnerability in Delta Sql 1.8.2 allows attackers to upload malicious PHP files and achieve remote code...

  • SecurityMay 31, 2026

    CVE-2026-10178: SQL Injection in Online Music Site 1.0 Admin Panel

    A remotely exploitable SQL injection vulnerability has been disclosed in code-projects Online Music Site 1.0, affecting the Administrator PHP AdminEditAlbum…

  • SecurityMay 30, 2026

    CVE-2026-7465: RCE in Spectra Gutenberg Blocks WordPress Plugin (CVSS 8.8)

    A high-severity remote code execution vulnerability in the Spectra Gutenberg Blocks plugin for WordPress allows authenticated Contributor-level attackers...

  • SecurityMay 19, 2026

    CVE-2025-15609: Fortis for WooCommerce Plugin Leaks API

    The Fortis for WooCommerce WordPress plugin before version 1.3.1 exposes sensitive API keys to unauthenticated attackers, enabling unauthorized access to...

  • SecurityMay 18, 2026

    CVE-2026-8785: SQL Injection in Hospital Management System

    A high-severity SQL injection vulnerability (CVE-2026-8785, CVSS 7.3) has been disclosed in projectworlds Hospital Management System in PHP 1.0, allowing...

  • NewsMay 15, 2026

    Avada Builder WordPress Plugin Flaws Allow Site Credential

    Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files...

  • SecurityMay 12, 2026

    CVE-2025-61311: Reflected XSS in docuForm Managed Print

    A reflected cross-site scripting vulnerability in the dfm-menu_alerts.php component of GmbH Mecury docuForm v11.11c allows attackers to execute arbitrary...

  • SecurityMay 3, 2026

    CVE-2026-5324: WordPress Brizy Page Builder Unauthenticated

    The Brizy Page Builder plugin for WordPress contains a critical unauthenticated Stored Cross-Site Scripting flaw in versions up to 2.8.11, enabling...

  • SecurityApr 28, 2026

    CVE-2026-7224: SQL Injection in Pizzafy Ecommerce System 1.0

    A high-severity SQL injection vulnerability has been discovered in SourceCodester Pizzafy Ecommerce System 1.0, allowing remote attackers to manipulate...

  • SecurityApr 27, 2026

    CVE-2026-7077: SQL Injection in itsourcecode Courier

    A remotely exploitable SQL injection vulnerability has been disclosed in itsourcecode Courier Management System 1.0, affecting the edit_parcel.php file...

  • NewsApr 23, 2026

    Hackers Actively Exploiting Breeze Cache File Upload Bug in WordPress Attacks

    Threat actors are mass-exploiting a critical unauthenticated file upload vulnerability in the Breeze Cache WordPress plugin, uploading PHP webshells to...

  • SecurityApr 23, 2026

    CVE-2026-3844 — Breeze Cache WordPress Plugin

    A critical unauthenticated file upload vulnerability in the Breeze Cache WordPress plugin allows attackers to upload arbitrary files to affected servers...

  • SecurityApr 20, 2026

    CVE-2026-6595: SQL Injection in ProjectsAndPrograms School

    A medium-severity SQL injection vulnerability has been disclosed in ProjectsAndPrograms School Management System, allowing remote attackers to manipulate...

  • SecurityApr 10, 2026

    CVE-2026-6004: SQL Injection in code-projects Simple IT

    A remotely exploitable SQL injection vulnerability has been disclosed in code-projects Simple IT Discussion Forum 1.0, affecting the /delete-category.php...

  • SecurityApr 6, 2026

    CVE-2026-5554: SQL Injection in Concert Ticket Reservation

    A remotely exploitable SQL injection vulnerability has been disclosed in code-projects Concert Ticket Reservation System 1.0, affecting the...

  • SecurityApr 6, 2026

    CVE-2026-5555: SQL Injection in Concert Ticket Reservation

    An unauthenticated SQL injection vulnerability has been disclosed in code-projects Concert Ticket Reservation System 1.0, affecting the login.php file via...

  • SecurityApr 6, 2026

    CVE-2026-5575: SQL Injection in SourceCodester Record

    A remotely exploitable SQL injection vulnerability has been disclosed in SourceCodester/jkev Record Management System 1.0, affecting the Login page's...

  • SecurityApr 5, 2026

    CVE-2026-5551: SQL Injection in itsourcecode Free Hotel

    A remotely exploitable SQL injection vulnerability has been disclosed in itsourcecode Free Hotel Reservation System 1.0, affecting the login page's email...

  • SecurityMar 29, 2026

    CVE-2026-5017: SQL Injection in code-projects Simple Food

    A remotely exploitable SQL injection vulnerability has been disclosed in code-projects Simple Food Order System 1.0, affecting the /all-tickets.php file...

  • SecurityMar 29, 2026

    CVE-2026-5018: SQL Injection in code-projects Simple Food

    A remotely exploitable SQL injection vulnerability exists in code-projects Simple Food Order System 1.0, where the Name parameter in register-router.php...

  • SecurityMar 29, 2026

    CVE-2026-5019: SQL Injection in code-projects Simple Food

    A SQL injection vulnerability has been disclosed in code-projects Simple Food Order System 1.0, where the Status parameter in all-orders.php enables...

  • SecurityMar 29, 2026

    CVE-2026-5033: SQL Injection in code-projects Accounting

    A remotely exploitable SQL injection vulnerability has been disclosed in code-projects Accounting System 1.0, where the cos_id parameter in...

  • SecurityMar 29, 2026

    CVE-2026-5034: SQL Injection in code-projects Accounting

    A remotely exploitable SQL injection vulnerability has been disclosed in code-projects Accounting System 1.0, allowing unauthenticated attackers to...

  • SecurityMar 17, 2026

    CVE-2015-20118: Stored XSS in RealtyScript 4.0.2 Admin

    A stored cross-site scripting vulnerability in RealtyScript 4.0.2 allows attackers to inject malicious JavaScript via the location_name parameter in the...

  • NewsMar 14, 2026

    AppsFlyer Web SDK Supply Chain Attack Spread

    Attackers hijacked AppsFlyer's CDN domain via a registrar incident, serving a sophisticated 170 KB crypto-stealing JavaScript payload to every site...

  • SecurityMar 9, 2026

    CVE-2026-3730: SQL Injection in itsourcecode Free Hotel

    A remotely exploitable SQL injection vulnerability has been disclosed in itsourcecode Free Hotel Reservation System 1.0, affecting the amenities admin...

  • SecurityMar 9, 2026

    CVE-2026-3734: Improper Authorization in SourceCodester

    A remotely exploitable improper authorization vulnerability has been disclosed in SourceCodester Client Database Management System 1.0, allowing...

  • SecurityMar 9, 2026

    CVE-2026-3740: SQL Injection in itsourcecode University

    A high-severity SQL injection vulnerability has been disclosed in itsourcecode University Management System 1.0, allowing remote attackers to execute...

  • SecurityMar 7, 2026

    CVE-2018-25165: SQL Injection Disclosed in Galaxy Forces MMORPG

    A SQL injection vulnerability in Galaxy Forces MMORPG version 0.5.8 has been formally catalogued by NVD, enabling authenticated attackers to extract...

  • SecurityFeb 12, 2026

    Critical RCE in WPvivid Backup Plugin Threatens 900,000+

    A critical unauthenticated arbitrary file upload vulnerability in the WPvivid Backup & Migration plugin allows remote code execution on over 900,000...

  • SecurityFeb 5, 2026

    NGINX TLS Vulnerability Enables Man-in-the-Middle Attacks

    CVE-2026-1642 affects NGINX OSS and Plus when proxying to upstream TLS servers, allowing attackers to inject plaintext data into responses.

  • SecurityJan 25, 2026

    WordPress Plugin Vulnerability (CVSS 10.0) Under Active

    Maximum severity flaw in Modular DS WordPress plugin allows unauthenticated privilege escalation. All versions through 2.5.1 affected with active...