Articles
Newsflash
11 Aug 2026 Business and Enterprise Solutions
Joomla: Reflected XSS vulnerability in Phoca Commander

In Phoca Commander component for Joomla versions 6.1.1 and earlier a medium severity vulnerability CVE-2026-65764 was detected. This vulnerability allows attackers to execute arbitrary scripts in the user’s browser. To address this issue, users should upgrade Phoca Commander to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-65764.

Read more
CMS
11 Aug 2026 Business and Enterprise Solutions
Joomla: Path Traversal in Phoca Commander

In Phoca Commander component for Joomla versions 6.1.1 and earlier a medium severity vulnerability CVE-2026-65765 was detected. This vulnerability allows attackers to access unauthorized files on the server. To address this issue, users should upgrade Phoca Commander to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-65765.

Read more
CMS
11 Aug 2026 Business and Enterprise Solutions
Joomla: Unauthenticated SQL injection in SP Page Builder

In the SP Page Builder component for Joomla versions before 6.7.1 a critical severity vulnerability CVE-2026-65766 was detected. This vulnerability allows attackers to perform an SQL injection. To address this issue, users should upgrade SP Page Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-65766.

Read more
CMS
11 Aug 2026 Business and Enterprise Solutions
Joomla: Authenticated SQL injection in SP Page Builder

In SP Page Builder component for Joomla versions prior to 6.7.1 a high severity vulnerability CVE-2026-65877 was detected. This vulnerability allows an authenticated attacker to execute arbitrary SQL commands on the database. To address this issue, users should upgrade SP Page Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-65877.

Read more
CMS
11 Aug 2026 Business and Enterprise Solutions
Directus: Authenticated Time-Based SQL Injection via PostGIS Collection Creation

In Directus versions prior to 12.1.0 a high severity vulnerability CVE-2026-10716 was detected. This vulnerability allows an authenticated administrator to execute arbitrary SQL commands, potentially leading to unauthorized data extraction via time-based blind SQL Injection (SQLi). This occurs during the collection creation flow when the instance uses PostgreSQL with the PostGIS extension enabled. By supplying a malicious fields[].type value that starts with geometry but is followed by attacker-controlled SQL syntax, an attacker can bypass input validation and manipulate the underlying database queries. To address this issue, users should upgrade Directus to version 12.1.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-10716.

Read more
CMS
10 Aug 2026 DevOps
Kubernetes: Arbitrary file creation in Java client library

In the Kubernetes Java client library component for Kubernetes in unspecified versions a unknown severity vulnerability CVE-2026-15687 was detected. This vulnerability allows a compromised pod to create new files in arbitrary locations on the client machine. To address this issue, users should upgrade the Kubernetes Java client library to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15687.

Read more
Developer Tools
Case Studies