ZeroHour

Search: “cms”

552 stories

[20260802] - Core - Improper CORS origin validation

Joomla patches CVE-2026-71573, improper CORS origin validation in CMS requests, in versions 5.4.8 and 6.1.3.

Joomla disclosed improper CORS origin validation (CVE-2026-71573), where configured CORS origins were not properly validated on CORS requests, rated moderate impact/severity and moderate probability. It affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2. Fixed in Joomla 5.4.8 and 6.1.3; reported on 2026-07-09 by Agamemnon Fakas and caveeroo.

Joomla Security Centre · Aug 17, 2026AdvisoryCVE-2026-71573

Plug 'n' Pray: Agentic LLM-based Detection of Potential Log File Exposures in Third-Party Content Management System Plugins

Agentic LLM analysis validates 79 log file exposures across 62 of the 300 most-installed WordPress plugins, covering 250M+ active installations.

Researchers built an agentic LLM-based framework combining static and dynamic analysis to automatically detect insecure log files created by WordPress plugins. Scanning the 300 most-installed plugins, which account for roughly 75% of all active installations in the official ecosystem, it produced 81 findings with 79 manually reproduced across 62 plugins. Insufficiently secured log files can disclose credentials and personal data and have led to website compromises. The authors derive a taxonomy of log path and protection patterns and best practices, finding multi-layered protection often absent.

arXiv cs.CR · 1d agoResearch

Metasploit Wrap Up: Lot of summer shells and fit http profiles

Metasploit 6.5 ships 13 new modules including RCEs for SonicWall SMA1000, Ghost CMS, Joomla JCE and Langflow, plus a Linux kernel LPE.

Rapid7's Metasploit wrap-up covers the 6.5 release, which adds 13 new modules, including remote code execution exploits for WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard and a Pix-for-WooCommerce plugin. The Fragnesia Linux kernel local privilege escalation (CVE-2026-46300) also landed. The release introduces HTTP malleable profiles, MCP functionality, Linux multi-fetch payloads and improved Windows on ARM support.

Rapid7 Blog · Aug 14, 2026ToolsCVE-2026-46300