Articles
Newsflash
29 Sep 2026 Communication and Collaboration
Open Notebook: Server-Side Request Forgery Vulnerability

In Open Notebook versions before 1.11.0 a high severity vulnerability CVE-2026-90769 was detected. This vulnerability allows authenticated users to perform server-side requests to internal services. To address this issue, users should upgrade Open Notebook to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-90769.

Read more
Communication
29 Sep 2026 Data Management and Analytics
PostgreSQL: Denial of Service in PostGIS

In PostGIS component for PostgreSQL versions 3.7.0 and earlier a medium severity vulnerability CVE-2026-90775 was detected. This vulnerability allows attackers to cause the backend process to crash, leading to a denial of service. To address this issue, users should upgrade PostGIS to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-90775.

Read more
Database
29 Sep 2026 DevOps
Strapi: Stored Cross-Site Scripting Vulnerability

In Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 a high severity vulnerability CVE-2026-90561 was detected. This vulnerability allows an authenticated user with author-level privileges to achieve account takeover of an administrator’s account. To address this issue, users should upgrade Strapi to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-90561.

Read more
Application Development
29 Sep 2026 Business and Enterprise Solutions
WordPress: Arbitrary Script Injection in GenieWords

In GenieWords component for WordPress versions 1.5.34 and earlier a high severity vulnerability CVE-2026-74933 was detected. This vulnerability allows unauthenticated users to overwrite its configuration and inject arbitrary web scripts. To address this issue, users should upgrade GenieWords to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-74933.

Read more
CMS
29 Sep 2026 DevOps
LibreNMS: SQL Injection Vulnerability

In LibreNMS version 1.65 and earlier a medium severity vulnerability CVE-2020-15875 was detected. This vulnerability allows a remote authenticated attacker to extract all information from the database via SQL injection. To address this issue, users should upgrade LibreNMS to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2020-15875.

Read more
Monitoring
28 Sep 2026 Business and Enterprise Solutions
WordPress: Stored Cross-Site Scripting Vulnerability in Aruba HiSpeed Cache plugin

In Aruba HiSpeed Cache component for WordPress versions 3.0.14 and earlier a medium severity vulnerability CVE-2026-15889 was detected. This vulnerability allows authenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade Aruba HiSpeed Cache plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15889.

Read more
CMS
Case Studies