Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash

Our news and updates

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Choose category
    • Communication
      • Communication
    • Communication and Collaboration
      • Utility
      • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    26 Nov 2025 Business and Enterprise Solutions
    WordPress: Unauthorized Data Modification in Autochat Automatic Conversation Plugin

    In Autochat Automatic Conversation plugin versions up to and including 1.1.9 a medium severity vulnerability CVE-2025-12043 was detected. This vulnerability allows unauthenticated attackers to connect and disconnect client IDs due to a missing capability check on the wp_ajax_nopriv_auycht_saveCid AJAX endpoint. To address this issue, users should upgrade the plugin to version 1.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12043.

    Read more
    CMS
    25 Nov 2025 Data Management and Analytics
    MongoDB: Invariant Failure in Batched Delete Handling Allows Server Crash

    In MongoDB Server versions 7.0 prior to 7.0.26, 8.0 prior to 8.0.13, and 8.1 prior to 8.1.2 a high severity vulnerability CVE-2025-13644 was detected. The issue allows a batched delete operation to trigger an invariant failure and crash the server when MongoDB incorrectly assumes multiple documents are present in a batch solely because a document exceeds BSONObjMaxSize. To address this issue, users should update to MongoDB Server 7.0.26, 8.0.13, or 8.1.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13644.

    Read more
    Database
    25 Nov 2025 Data Management and Analytics
    MongoDB: Privilege Escalation Allowing Query Termination Causing Denial of Service

    In MongoDB Server versions 7.0 prior to 7.0.26 and 8.0 prior to 8.0.14 a medium severity vulnerability CVE-2025-13643 was detected. This vulnerability allows a user with limited cluster privileges to terminate queries executed by other users, potentially causing denial of service by preventing some queries from completing successfully. To address this issue, users should upgrade MongoDB Server to versions 7.0.26, 8.0.14, or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13643.

    Read more
    Database
    25 Nov 2025 Data Management and Analytics
    MongoDB: TLS Certificate Validation Bypass on Windows and Apple Servers

    In MongoDB Server versions 7.0 prior to 7.0.26, 8.0 prior to 8.0.16, and 8.2 prior to 8.2.2 a medium severity vulnerability CVE-2025-12893 was detected. This vulnerability allows MongoDB servers running on Windows or Apple platforms to successfully complete TLS handshakes with client or server certificates that do not meet the documented Extended Key Usage (EKU) requirements. Specifically, certificates missing the clientAuth EKU may still authenticate as clients, and on Apple servers, certificates missing the serverAuth EKU may still authenticate as servers during egress TLS connections. To address this issue, users should upgrade MongoDB Server to versions 7.0.26, 8.0.16, or 8.2.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12893.

    Read more
    Database
    25 Nov 2025 Business and Enterprise Solutions
    WordPress: Reflected Cross-Site Scripting in eCommerce Plugin

    In WordPress eCommerce Plugin versions up to and including 2.9.0 a high severity vulnerability CVE-2024-14015 was detected. This vulnerability allows attackers to perform reflected cross-site scripting (XSS) by exploiting unsanitized and unescaped parameters output back on the page, which could be used against high privilege users such as administrators. To address this issue, users should upgrade the plugin to a version later than 2.9.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-14015.

    Read more
    CMS
    25 Nov 2025 Business and Enterprise Solutions
    WordPress: Time-Based SQL Injection in Perfect Brands for WooCommerce Plugin

    In Perfect Brands for WooCommerce plugin versions up to and including 3.6.2 a medium severity vulnerability CVE-2025-10144 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to perform time-based SQL injection via the brands attribute of the products shortcode, due to insufficient escaping and lack of proper SQL query preparation. Exploiting this flaw can enable extraction of sensitive database information. To address this issue, users should upgrade the plugin to version 3.6.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-10144.

    Read more
    CMS
    24 Nov 2025 Infrastructure and Network
    Wazuh: NULL Pointer Dereference in fim_alert() Allows Analysisd Crash

    In Wazuh versions 3.7.0 through 4.11.x a medium severity vulnerability CVE-2025-64169 was detected. This vulnerability allows a compromised agent to crash the `analysisd` process on the Wazuh manager due to a NULL pointer dereference in the `fim_alert()` function when `oldsum->md5` is not properly checked. To address this issue, users should upgrade Wazuh to versions 4.12.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-64169.

    Read more
    Security
    24 Nov 2025 DevOps
    Terraform Enterprise: Improper Permission Handling Allows Unauthorized State Version Creation

    In Terraform Enterprise versions prior to 1.1.1 and 1.0.3 a medium severity vulnerability CVE-2025-13432 was detected. This vulnerability allows users with specific but insufficient permissions to create Terraform state versions in a workspace, potentially enabling infrastructure alteration if a subsequent plan operation is approved or auto-applied. To address this issue, users should upgrade Terraform Enterprise to versions 1.1.1, 1.0.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13432.

    Read more
    Developer Tools
    24 Nov 2025 Infrastructure and Network
    Wazuh: Missing ACL on authd.pass Exposes Passwords on Windows

    In Wazuh versions 4.3.0 through 4.12.x a low severity vulnerability CVE-2025-54866 was detected. This vulnerability allows all authenticated users on a Windows machine to access the `authd.pass` file due to missing access control lists (ACLs) on `C:\Program Files (x86)\ossec-agent\authd.pass`, exposing sensitive passwords. To address this issue, users should upgrade Wazuh to version 4.13.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-54866.

    Read more
    Security
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Cookie Settings

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}