In Phoca Commander component for Joomla versions 6.1.1 and earlier a medium severity vulnerability CVE-2026-65764 was detected. This vulnerability allows attackers to execute arbitrary scripts in the user’s browser. To address this issue, users should upgrade Phoca Commander to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-65764.
Read more CMSIn Phoca Commander component for Joomla versions 6.1.1 and earlier a medium severity vulnerability CVE-2026-65765 was detected. This vulnerability allows attackers to access unauthorized files on the server. To address this issue, users should upgrade Phoca Commander to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-65765.
Read more CMSIn the SP Page Builder component for Joomla versions before 6.7.1 a critical severity vulnerability CVE-2026-65766 was detected. This vulnerability allows attackers to perform an SQL injection. To address this issue, users should upgrade SP Page Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-65766.
Read more CMSIn SP Page Builder component for Joomla versions prior to 6.7.1 a high severity vulnerability CVE-2026-65877 was detected. This vulnerability allows an authenticated attacker to execute arbitrary SQL commands on the database. To address this issue, users should upgrade SP Page Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-65877.
Read more CMSIn Directus versions prior to 12.1.0 a high severity vulnerability CVE-2026-10716 was detected. This vulnerability allows an authenticated administrator to execute arbitrary SQL commands, potentially leading to unauthorized data extraction via time-based blind SQL Injection (SQLi). This occurs during the collection creation flow when the instance uses PostgreSQL with the PostGIS extension enabled. By supplying a malicious fields[].type value that starts with geometry but is followed by attacker-controlled SQL syntax, an attacker can bypass input validation and manipulate the underlying database queries. To address this issue, users should upgrade Directus to version 12.1.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-10716.
In SAML Single Sign On – SSO Login component for WordPress versions up to and including 5.4.4 a critical severity vulnerability CVE-2026-15981 was detected. This vulnerability allows attackers to bypass authentication. To address this issue, users should upgrade SAML Single Sign On – SSO Login to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15981.
Read more CMS