WordPress content injection flaw abused in defacement campaignsSecurity Affairs·Feb 7, 14:43 UTC · Feb 7, 2017Threat actor60
Recent WordPress flaw exploited to deface more than 1.5 million web sitesSecurity Affairs·Feb 11, 09:11 UTC · Feb 11, 2017Exploit / PoC60
Massive hacking campaign on Joomla sites via recently patched flawsSecurity Affairs·Oct 31, 08:37 UTC · Oct 31, 2016Vulnerability in the wildCVE-2016-8870CVE-2016-886960
Old CVE-2014-3704 flaw in Drupal still exploited in attacksSecurity Affairs·Mar 29, 12:07 UTC · Mar 29, 2018VulnerabilityCVE-2014-370460
A e-skimmer found on WordPress site using the WooCommerce pluginSecurity Affairs·Apr 12, 10:43 UTC · Apr 12, 2020Data breach60
Critical SQL Injection CVE-2017-8917 vulnerability patched in Joomla, update it now!Security Affairs·May 18, 07:39 UTC · May 18, 2017VulnerabilityCVE-2017-8917CVE-2016-8870CVE-2016-886960
Zero-day Content Injection Vulnerability found in WordPressSecurity Affairs·Feb 2, 07:12 UTC · Feb 2, 2017Exploit / PoC60
Crooks leverages .htaccess injector on Joomla and WordPress sites for malicious redirectsSecurity Affairs·May 27, 12:39 UTC · May 27, 2019Exploit / PoCCVE-2018-920660
Critical WordPress REST API Bug: Prevent Your Blog From Being Hacked!The Hacker News·Feb 2, 08:24 UTC · Feb 2, 2017Exploit / PoC in the wild60
WordPress kept users and hackers in the dark while secretly fixing critical zero-dayHelp Net Security·Feb 2, 00:00 UTC · Feb 2, 2017Exploit / PoC in the wild60
Hackers Exploit WordPress mu-Plugins to Inject Spam and Hijack Site ImagesThe Hacker News·Apr 1, 05:37 UTC · Apr 1, 2025Data breachCVE-2024-27956CVE-2024-8353CVE-2024-434560
GiveWP WordPress Plugin Vulnerability Puts 100,000+ Websites at RiskThe Hacker News·Aug 21, 04:35 UTC · Aug 21, 2024VulnerabilityCVE-2024-5932CVE-2024-6500CVE-2024-7094+4 CVEs60
New Flaw in WordPress Plugin Used by Over a Million Sites Under Active ExploitationThe Hacker News·May 20, 04:02 UTC · May 20, 2023Exploit / PoC in the wildCVE-2023-3224360
Cloudflare not fully backing out of Russia, company says, as tech firms are forced to weigh inCyberScoop·Mar 7, 19:39 UTC · Mar 7, 2022Exploit / PoC in the wild60
Experts warn threat actors are scanning the web for Drupal installs vulnerable to Drupalgeddon2Security Affairs·Apr 13, 18:59 UTC · Apr 13, 2018Threat actorCVE-2018-760060
SQLi flaw in the NextGEN Gallery plugin exposes at risk of hack more than 1 Million WordPress InstallsSecurity Affairs·Mar 1, 11:00 UTC · Mar 1, 2017Exploit / PoC in the wild60
⚡ Weekly Recap: Chrome 0-Day, Data Wipers, Misused Tools and ZeroThe Hacker News·Jul 25, 08:27 UTC · Jul 25, 2026Malware in the wildCVE-2025-20286CVE-2025-49113CVE-2025-5419+8 CVEs60
CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code ExecutionThe Hacker News·Jun 17, 12:17 UTC · Jun 17, 2026Advisory in the wildCVE-2026-4890760
Critical WordPress Anti-Spam Plugin Flaws Expose 200,000+ Sites to Remote AttacksThe Hacker News·Dec 2, 04:54 UTC · Dec 2, 2024VulnerabilityCVE-2024-10542CVE-2024-1078160
Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress SitesThe Hacker News·May 8, 14:05 UTC · May 8, 2024Vulnerability in the wildCVE-2023-4000060
Hacked WordPress Sites Abusing Visitors' Browsers for Distributed BruteThe Hacker News·Mar 7, 13:45 UTC · Mar 7, 2024RansomwareCVE-2021-443660
WordPress Plugin Alert - Critical SQLi Vulnerability Threatens 200K+ WebsitesThe Hacker News·Feb 27, 05:43 UTC · Feb 27, 2024Vulnerability in the wildCVE-2024-1071CVE-2023-346060
WooCommerce Patches Critical Plugin Flaw Affecting Half a Million SitesInfosecurity Magazine·Mar 24, 17:00 UTC · Mar 24, 2023Vulnerability in the wild60
Critical flaw in WooCommerce Payments plugin allows site takeoverSecurity Affairs·Mar 24, 14:45 UTC · Mar 24, 2023Exploit / PoC in the wild60
Critical WooCommerce Payments Plugin Flaw Patched for 500,000+ WordPress SitesThe Hacker News·Mar 24, 07:51 UTC · Mar 24, 2023Vulnerability in the wild60
Week in review: RCE bug in GitLab patched, phishing PyPI users, Escanor malware in MS Office docsHelp Net Security·Aug 28, 00:00 UTC · Aug 28, 2022VulnerabilityCVE-2022-2884160
Experts Notice Sudden Surge in Exploitation of WordPress Page Builder Plugin VulnerabilityThe Hacker News·Jul 18, 15:12 UTC · Jul 18, 2022Vulnerability in the wildCVE-2021-2428460
Week in review: F5 BIG-IP flaw, critical bugs in Aruba and Avaya network switches, Patch Tuesday forecastHelp Net Security·May 8, 00:00 UTC · May 8, 2022VulnerabilityCVE-2022-138860
BEC scammer infects own device, giving researchers a frontCyberScoop·Mar 4, 18:12 UTC · Mar 4, 2021Phishing & fraud in the wild60
Magento sites under attack through easily exploitable SQLi flawHelp Net Security·Apr 8, 00:00 UTC · Apr 8, 2019Exploit / PoC in the wild60
Magento Attacked Through Card Skimming ExploitSecurity Affairs·Apr 6, 08:09 UTC · Apr 6, 2019Exploit / PoC60
Hackers Have Started Exploiting Drupal RCE Exploit Released YesterdayThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2018VulnerabilityCVE-2018-760060
Latest Joomla 3.7.1 Release Patches Critical SQL Injection AttackThe Hacker News·May 18, 07:41 UTC · May 18, 2017VulnerabilityCVE-2017-891760
Drupal releases security updates to fix four vulnerabilities in versions 7, 8Security Affairs·Nov 18, 07:07 UTC · Nov 18, 2016VulnerabilityCVE-2014-370460
Most unpatched Joomla sites compromised in latest wave of attacksHelp Net Security·Oct 31, 00:00 UTC · Oct 31, 2016Vulnerability in the wildCVE-2016-8870CVE-2016-886960