Articles
Newsflash
18 Jun 2025 DevOps
Portainer: HTTP Header Exposure Vulnerability in CE via Malicious Container Registry

In Portainer Community Edition versions prior to STS 2.31.0 and LTS 2.27.7 a medium severity vulnerability CVE-2025-49593 was detected. This vulnerability allows HTTP headers – including registry authentication credentials or Portainer session tokens – to be leaked if a Portainer administrator registers a malicious container registry or if an existing registry is compromised. To address this issue, users should upgrade Portainer CE or BE version 2.31.0 or later for STS, or version 2.27.7 or later for LTS. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49593.

Read more
Developer Tools
18 Jun 2025 Data Management and Analytics
Grafana: Improper Input Validation Vulnerability in Leading to Browser Unresponsiveness

In Grafana versions before 11.6.2 a low severity vulnerability CVE-2025-1088 was detected. This vulnerability allows excessively long dashboard titles or panel names to cause Chromium-based browsers to become unresponsive due to improper input validation. To address this issue, users should upgrade Grafana to versions 11.6.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1088.

Read more
Data Analytics
18 Jun 2025 Business and Enterprise Solutions
WordPress: Arbitrary File Upload Vulnerability in CSV Me Plugin

In CSV Me plugin for WordPress versions up to and including 2.0 a high severity vulnerability CVE-2025-6086 was detected. This vulnerability allows authenticated attackers with Administrator-level access and above to upload arbitrary files due to insufficient file type validation, potentially leading to remote code execution. Currently, there is no fixed version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6086.

Read more
CMS
18 Jun 2025 Business and Enterprise Solutions
WordPress: Stored XSS Vulnerability in Target Video Easy Publish Plugin

In Target Video Easy Publish plugin for WordPress versions up to and including 3.8.5 a medium severity vulnerability CVE-2025-5237 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via the ‘width’ parameter due to insufficient input sanitization and output escaping. To address this issue, users should update Target Video Easy Publish plugin to versions 3.8.6 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5237.

Read more
CMS
18 Jun 2025 Business and Enterprise Solutions
WordPress: Stored XSS Vulnerability in tarteaucitron.io Plugin

In tarteaucitron.io plugin for WordPress versions before 1.9.5 a medium severity vulnerability CVE-2025-4955 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to perform Stored Cross-Site Scripting (XSS) attacks by exploiting unsanitized query parameters from YouTube oEmbed URLs. To address this issue, users should upgrade tarteaucitron.io plugin to versions 1.9.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4955.

Read more
CMS
17 Jun 2025 Business and Enterprise Solutions
Liferay: Denial-of-Service Vulnerability in GraphQL Query Handling

In Liferay Portal versions 7.4.0 through 7.4.3.97, Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35 and 7.2 fix pack 8 through fix pack 20 a high severity vulnerability CVE-2025-3602 was detected. This vulnerability allows attackers to perform denial-of-service (DoS) attacks by executing overly complex GraphQL queries due to the absence of query depth limitations. To address this issue, users should upgrade Liferay Portal to versions 7.4.3.98, Liferay DXP to versions 2023.Q3.3 or 7.3 U36. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3602.

Read more
CMS
Case Studies