Tag: web application security
34 articles

Avada WordPress Theme Flaw Enables Zero-Click Remote Code Execution
A critical vulnerability in the Avada WordPress theme, scored 9.8 out of 10, can be exploited through a zero-click remote code execution attack, allowing hackers to run malicious PHP code on affected sites without needing login credentials. This flaw enables attackers to take full control of a site, planting malware, stealing data, or creating rogue admin accounts.

GitLab Flaw Exploited in Wild Days After Disclosure
In a chilling demonstration of the new reality in vulnerability exploitation, attackers began exploiting a newly disclosed GitLab flaw within minutes of its public disclosure, leaving little time for patching. This rapid reproduction and exploitation is a stark reminder that waiting for the next patch cycle may no longer be a viable defense strategy.

Elementor Pro Flaw Enables Unauthenticated Code Execution
A critical vulnerability in Elementor Pro, rated CVSS 9.0, allows hackers to execute malicious code remotely - and it's surprisingly easy to exploit, thanks to a logic flaw in the plugin's Forms module. This loophole lets attackers bypass security checks and write PHP files to a public uploads directory.

CISA Mandates Swift Fix for Exploited Ray RCE Flaw
A critical bug in the Ray framework, scoring 9.4 under CVSS v4, can be exploited for remote code execution with a simple visit to a malicious web page or hostile ad in Firefox or Safari. This vulnerability can be triggered when an attacker crafts requests that appear browser-originated, allowing for a potentially disastrous security breach.

CSS Attacks Break Webmail Defenses to Steal Passwords and Tokens
Researchers have discovered alarming proof-of-concept techniques that allow attackers to exploit styled HTML in emails, breaking through webmail defenses to steal passwords, tokens, and even hijack trusted actions. This vulnerability affects major email services including Outlook, Gmail, and Yahoo Mail, and public proof-of-concept code is readily available.

WordPress Fixes Pre-Auth XSS Flaw That Enables PHP Code Execution
WordPress has patched a high-severity flaw that could let attackers inject malicious code into your site - and it's crucial you update ASAP, as 41.2% of all websites are potentially vulnerable.

AI Research Exposes Novel HTTP Desync Techniques and Apache Zero-Day
Meet HTTP Terminator, an AI-powered research system that generated 30,000 candidate desync vectors and helped uncover novel HTTP desynchronization techniques, including an Apache Traffic Server zero-day. This groundbreaking tech scanned 30,000 websites, pushing the boundaries of vulnerability discovery.

Rails Flaw Exposes Server Files to Unauthenticated Attackers
A critical security flaw in Rails, known as CVE-2026-66066, could let hackers read sensitive files from your server, including secret keys, database passwords, and API tokens, by exploiting image uploads. This vulnerability affects various Rails releases, including versions 7.0.0 through 7.2.3.1, 8.0.0 through 8.0.5, and 8.1.0 through 8.1.3.

vBulletin Flaw Exploits Unpatched Servers
A critical vBulletin security flaw, tracked as CVE-2026-61511, leaves unpatched servers vulnerable to attacks, allowing hackers to execute malicious PHP code and putting forum operators and their communities at risk. This exploit affects vBulletin versions 5.x and 6.x, up to 5.7.5 and 6.2.1, respectively.

Exploit for Patched vBulletin Flaw Disclosed
A newly disclosed exploit for a patched vBulletin flaw shows how an unauthenticated request can be used to execute code on an unpatched forum server, putting vulnerable sites at risk. This security threat was made public on July 27, highlighting the importance of keeping software up to date.

Malvertising Campaign Exploits Browsers to Assemble Malware in Memory
Meet the sneaky malvertising campaign that's turning web browsers into malware factories, assembling attacks entirely in memory using fake pages for popular services like Solana, Luno, and TradingView. This stealthy operation has been active since late 2024, targeting users across 12 countries and 25 languages.

WordPress Sites Targeted as Hackers Exploit Critical wp2shell Flaws
Hackers are actively exploiting critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to inject malicious plugins and PHP webshells, putting countless sites at risk. Attackers are using mass-scanning and plugin upload abuse to gain control, making it essential for WordPress users to take immediate action.

WordPress Sites Targeted as Public Exploits Emerge for wp2shell Flaws
A critical vulnerability in WordPress Core, dubbed "wp2shell," has been discovered, allowing hackers to remotely execute code on affected sites - putting your online presence at risk if you haven't updated yet. Immediate action is urged for site operators to protect against this high-severity threat.

Attackers Exploit Joomla Extension Bugs with Perfect 10 Scores
Critical vulnerabilities in two popular Joomla extensions have been exploited in the wild, allowing attackers to gain remote control of affected sites by uploading malicious files. The Cybersecurity and Infrastructure Security Agency has sounded the alarm, adding the flaws to its Known Exploited Vulnerabilities catalog.

CISA Warns of Exploited Flaws in Joomla Extensions
Stay safe online: a critical vulnerability in the iCagenda extension for Joomla can allow attackers to upload malicious files and take control of your website, leading to data theft and total site compromise. CISA warns that this flaw, tracked as CVE-2026-48939, is being actively exploited, so take action now to protect your site.

Joomla Flaws Exploited as Zero-Days in Active Attacks
A critical vulnerability in the iCagenda extension for Joomla, known as CVE-2026-48939, has been exploited as a zero-day since June 15, 2026, allowing attackers to upload arbitrary files via the component's file attachment feature. This severe flaw, scoring 10.0 on the CVSS scale, has already sparked a wave of automated attacks against popular content-management-system extensions.

WordPress Plugins Compromised to Deploy Hidden Backdoors
Over 1.2 million WordPress sites are potentially at risk after a security breach compromised three popular plugins, allowing hackers to secretly install backdoors and gain admin access. The sneaky attack injects malicious code that only kicks in when a logged-in administrator visits the site, putting unsuspecting site owners in the dark.

phpBB Flaw Enables Instant Account Takeover
A single HTTP request can give an attacker instant access to any user's account, including administrator accounts, without needing a password - a vulnerability rated 9.4 on the CVSS scale that's affecting phpBB versions up to 3.3.16 and 4.0.0 alpha.

GitHub Dev Attack Exploits OAuth Tokens
A single click can be all it takes for an attacker to swipe a GitHub token, giving them free rein to read and write to your private repos. Security researcher Ammar Askar warns that a clever exploit in GitHub.dev's web-based editor can turn a harmless link into a token-stealing threat.

Ghost CMS SQL flaw fuels large-scale ClickFix attacks
Over 700 domains were hit in a massive cyberattack that exploited a critical vulnerability in Ghost CMS, putting sensitive data at risk. The flaw, tracked as CVE-2026-26980, allowed hackers to tap into site databases and steal admin API keys.

Drupal Core SQL Injection Flaw Actively Exploited
Drupal has confirmed that exploit attempts for a critical SQL injection flaw, CVE-2026-9082, are being actively detected in the wild, posing a significant risk of privilege escalation and remote code execution. This vulnerability affects all supported Drupal Core versions and can lead to full site compromise if not addressed promptly.

Drupal Sites Targeted in SQL Injection Attacks
Drupal sites are under attack as SQL injection exploits are now being detected in the wild, taking advantage of a vulnerability that can be triggered without authentication. This critical flaw, CVE-2026-9082, allows attackers to execute arbitrary SQL and potentially run remote code, putting sites that use PostgreSQL at risk.

Drupal Flaw Exposes PostgreSQL Sites to Remote Code Execution Attacks
A vulnerability in Drupal Core's database abstraction API leaves PostgreSQL sites open to devastating SQL injection attacks, allowing hackers to send malicious requests and wreak havoc. This highly critical flaw, tracked as CVE-2026-9082, has been patched with urgent security updates.

Drupal Rushes Security Fix to Plug High-Risk Bug
Drupal is rushing out a critical security update today to fix a high-risk bug that could be exploited by hackers within hours of the patch being released. The update is a core security release aimed at plugging a vulnerability that poses a significant threat to users.