WordPress.org · Security·23h ago highWordPress 7.1.2 Release#wordpress#cve-2026-87902#rce 16 sources1
SecurityWeek·1d ago highWordPress Patches ‘Click2Shell’ Vulnerability#wordpress#click2shell#rce 6 sources 2 min
Ars Technica · AI·1d agoTrump admin using AI to deny medical care for seniors in disastrous experiment#cms#government-policy#healthcare-ai 10 min
Wordfence·2d agoWordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026)#wordpress#wordfence#vulnerability
Wordfence·4d ago highPSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core#wordpress#path-traversal#local-file-inclusion
Hacker News · security·4d ago highWordPress: Unauthenticated path traversal leading to conditional RCE#wordpress#path-traversal#rceVulnerability
GBHackers·8d agoWordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal#authorization-bypass#cms#patch 3 min
Cyber Security News·8d agoWordPress Urges Immediate Update After Fixing 11 Security Vulnerabilities#authorization-bypass#cms#path-traversal 3 min1
Patchstack·9d ago highWordPress 7.1.1 Maintenance and Security Release#cms#patch-release#stored-xss 5 min
WordPress.org · Security·9d agoWordPress 7.1.1 Maintenance and Security Release#cms#patching#path-traversal 4 min
Drupal Security Advisories·10d agoDrupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013#ckeditor#cms#drupalAdvisory
arXiv cs.CR·11d agoPlug 'n' Pray: Agentic LLM-based Detection of Potential Log File Exposures in Third-Party Content Management System Plugins#cms#llm-agents#log-exposureResearch
Full Disclosure·23d agoFlextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion#cms#file-inclusion#flextypeVulnerability 8 sources1
Exploit-DB·25d ago[webapps] Ghost_CMS 6.19.0 - Remote Code Execution#cms#ghost-cms#open-sourceExploit / PoC1
Exploit-DB·25d ago[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting#bludit#cms#exploit-dbExploit / PoC1
Joomla Security Centre·Aug 17, 2026[20260810] - Core - Unrestricted uploads of SHTML files#cms#code-execution#cve-2026-73373CVE-2026-73373
Joomla Security Centre·Aug 17, 2026[20260805] - Core - Improper ACL checks for category webservice endpoints#access-control#acl#apiCVE-2026-72532
Joomla Security Centre·Aug 17, 2026[20260804] - Core - Improper ACL checks for custom fields webservice endpoints#access-control#acl#cmsCVE-2026-72531
Joomla Security Centre·Aug 17, 2026[20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints#access-control#acl#apiCVE-2026-71574
Joomla Security Centre·Aug 17, 2026[20260802] - Core - Improper CORS origin validation#cms#cors#joomlaCVE-2026-71573
Joomla Security Centre·Aug 17, 2026[20260801] - Core - Response header injection in download views#cms#header-injection#joomlaCVE-2026-71572