Articles
Newsflash
17 Sep 2026 Infrastructure and Network
FreeIPA: Information Disclosure and Resource Exhaustion

In FreeIPA (unspecified versions) a medium severity vulnerability CVE-2026-11873 was detected. This vulnerability allows unauthenticated attackers to cause resource exhaustion through log amplification and expose internal stack traces. To address this issue, users should upgrade FreeIPA to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11873.

Read more
Security
17 Sep 2026 Business and Enterprise Solutions
WordPress: Stored Cross-Site Scripting in WPBakery Page Builder

In WPBakery Page Builder component for WordPress versions 8.7.4 and earlier a medium severity vulnerability CVE-2026-15101 was detected. This vulnerability allows authenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade WPBakery Page Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15101.

Read more
CMS
17 Sep 2026 Business and Enterprise Solutions
WordPress: PHP Object Injection in WP User Frontend

In WP User Frontend component for WordPress versions 4.3.10 and earlier a high severity vulnerability CVE-2026-81283 was detected. This vulnerability allows attackers to perform a PHP Object Injection. To address this issue, users should upgrade WP User Frontend to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-81283.

Read more
CMS
17 Sep 2026 Business and Enterprise Solutions
WordPress: Stored Cross-Site Scripting vulnerability in Welcart e-Commerce plugin

In Welcart e-Commerce plugin component for WordPress versions 2.12.1 and earlier a high severity vulnerability CVE-2026-19914 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade Welcart e-Commerce plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19914.

Read more
CMS
17 Sep 2026 Business and Enterprise Solutions
WooCommerce: Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce

In Upsell Order Bump Offer for WooCommerce component for WooCommerce versions 3.1.5 and earlier a high severity vulnerability CVE-2026-81288 was detected. This vulnerability allows unauthenticated attackers to perform Cross-Site Scripting attacks. To address this issue, users should upgrade Upsell Order Bump Offer for WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-81288.

Read more
E-commerce
16 Sep 2026 Business and Enterprise Solutions
Joomla: Unauthenticated Extension Deletion in miniOrange extensions

In miniOrange extensions component for Joomla a high severity vulnerability CVE-2026-78074 was detected. This vulnerability allows unauthenticated actors to delete arbitrary installed extensions. To address this issue, users should upgrade miniOrange extensions to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78074.

Read more
CMS
Case Studies