Articles
Newsflash
20 Jul 2026 DevOps
Forgejo: Stored cross-site scripting vulnerability

In Forgejo versions before 15.0.3 a medium severity vulnerability CVE-2026-59102 was detected. This vulnerability allows authenticated attackers to execute arbitrary JavaScript in other users’ browsers. To address this issue, users should upgrade Forgejo to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-59102.

Read more
Developer Tools
20 Jul 2026 DevOps
Plane: Out-of-bounds read vulnerability

In Plane versions 4.6.3 and earlier a critical severity vulnerability CVE-2026-38971 was detected. This vulnerability allows an attacker to access sensitive information or cause a denial of service. To address this issue, users should upgrade Plane to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-38971.

Read more
Developer Tools
20 Jul 2026 Business and Enterprise Solutions
WordPress: Arbitrary File Deletion Vulnerability in TinyPNG – JPEG, PNG & WebP image compression

In TinyPNG – JPEG, PNG & WebP image compression component for WordPress versions 3.6.13 and earlier a high severity vulnerability CVE-2026-7311 was detected. This vulnerability allows authenticated attackers to delete arbitrary files on the server, which can lead to remote code execution. To address this issue, users should upgrade TinyPNG – JPEG, PNG & WebP image compression to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-7311.

Read more
CMS
20 Jul 2026 Business and Enterprise Solutions
WordPress: Missing Authorization in weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

In weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot component for WordPress versions 2.3.0 and earlier a medium severity vulnerability CVE-2026-12729 was detected. This vulnerability allows attackers to execute sensitive operations without proper authorization. To address this issue, users should upgrade weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12729.

Read more
CMS
20 Jul 2026 Data Management and Analytics
Weaviate: Privilege Escalation Vulnerability

In Weaviate versions before 1.38.0 a high severity vulnerability CVE-2026-59093 was detected. This vulnerability allows an attacker to escalate their privileges. To address this issue, users should upgrade Weaviate to version 1.38.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-59093.

Read more
Database
17 Jul 2026 Business and Enterprise Solutions
WordPress: Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme

In Fitness Zone WordPress Theme component for WordPress versions 5.7 and earlier a high severity vulnerability CVE-2025-69155 was detected. This vulnerability allows attackers to inject malicious scripts. To address this issue, users should upgrade Fitness Zone WordPress Theme to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-69155.

Read more
CMS
Case Studies