Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash

Our news and updates

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Choose category
    • Communication
      • Communication
    • Communication and Collaboration
      • Utility
      • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    13 Nov 2024 Project and Agile Management
    Kanboard: Unrestricted File Access Vulnerability

    In Kanboard versions prior to 1.2.42 a critical severity vulnerability CVE-2024-51747 was detected. This vulnerability allows attackers to exploit misconfigured file paths in the database, enabling them to read or delete arbitrary files on the server. To fix this issue, users should upgrade Kanboard to version 1.2.42. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-51747.

    Read more
    Project Management
    13 Nov 2024 Specialized Software
    Moodle: XSS Vulnerability in H5P Error Messages

    In Moodle versions 4.1.0 and above, prior to 4.1.12, 4.2.0 and above, prior to 4.2.9, 4.3.0 and above, prior to 4.3.6, 4.4.0 and above, prior to 4.4.2 a medium severity vulnerability CVE-2024-43439 was detected. This vulnerability allows H5P error messages to be exploited for cross-site scripting attacks, requiring improved sanitization. To fix this issue, users need to update to versions 4.1.12, 4.2.9, 4.3.6, 4.4.2, or higher. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43439.

    Read more
    Educational
    13 Nov 2024 Specialized Software
    Moodle: Hidden Profile Fields Exposed in Gradebook

    In Moodle versions 4.4.0 and above, prior to 4.4.2, 4.3.0 and above, prior to 4.3.6, 4.2.0 and above, prior to 4.2.9, 4.1.0 and above, prior to 4.1.12 a medium severity vulnerability CVE-2024-43429 was detected. This vulnerability makes some hidden profile fields visible in gradebook reports. This allows users who shouldn’t see hidden fields to access them. To fix this issue, users need to update to versions 4.4.2, 4.3.6, 4.2.9, 4.1.12, or higher. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-43429.

    Read more
    Educational
    13 Nov 2024 Specialized Software
    Moodle: XSS Risk Due to Insufficient Data Sanitization During Restore

    In Moodle versions 4.4 to 4.4.1, 4.3 to 4.3.5, 4.2 to 4.2.8, 4.1 to 4.1.11 a medium severity vulnerability CVE-2024-43437 was detected. This vulnerability allows attackers to inject malicious scripts into Moodle’s backup restore process, potentially leading to cross-site scripting attacks when users restore maliciously crafted backup files. To fix this issue, users should upgrade Moodle to version 4.4.2, 4.3.6, 4.2.9 and 4.1.12. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-43437.

    Read more
    Educational
    13 Nov 2024 Project and Agile Management
    Kanboard: Arbitrary PHP Code Execution Vulnerability

    In Kanboard versions before 1.2.41 a high severity vulnerability CVE-2024-51748 was detected. This vulnerability allows attackers to execute arbitrary PHP code on the server by exploiting a misconfigured file path in the sqlite.db settings. To fix this issue, users should upgrade Kanboard to version 1.2.42. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-51748.

    Read more
    Project Management
    12 Nov 2024 Business and Enterprise Solutions
    WordPress: Malicious Script Injection via Crafted Links Allows Remote Code Execution

    In WordPress in all versions up to and including 1.9.244 a medium severity vulnerability CVE-2024-10647 was detected. This vulnerability allows attackers to inject malicious scripts into pages, which execute if a user clicks a specially crafted link. To fix this problem, users should upgrade to version 1.9.245. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10647.

    Read more
    CMS
    12 Nov 2024 Communication and Collaboration
    Mattermost: Private Channel Name Disclosure Vulnerability

    In Mattermost versions 10.0.x ≤ 10.0.0 and 9.11.x ≤ 9.11.2 a medium severity vulnerability, CVE-2024-52032, was detected. This vulnerability allows attackers to retrieve the names of private channels they are not a member of when using the channel switcher feature, provided Elasticsearch v8 is enabled. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-52032.

    Read more
    Communication
    12 Nov 2024 Communication and Collaboration
    Mattermost: Unauthorized Access to Private Channel Details

    In Mattermost versions 9.10.x up to 9.10.2, 9.11.x up to 9.11.1, 9.5.x up to 9.5.9 and 10.0.x up to 10.0.0 a low severity vulnerability CVE-2024-42000 was detected. This vulnerability allows attackers with “Read Groups” permission, but without access to specific channels, to retrieve details about private channels they are not members of by sending a request to /api/v4/channels. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-42000.

    Read more
    Communication
    12 Nov 2024 Communication and Collaboration
    Mattermost: Vulnerability in MFA Code Replay Protection

    In Mattermost versions 9.11.x up to 9.11.2 and 9.5.x up to 9.5.10 a low severity vulnerability CVE-2024-36250 was detected. This vulnerability allows attackers to reuse the MFA code within approximately 30 seconds, exploiting inadequate replay protection. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36250.

    Read more
    Communication
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Cookie Settings

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}