Collected every two hours from specialised publications — each link leads to the original article.
Release 1.7.2 Add HEAD request handler to the static.php Fix so the oauth_password_claim claim is retrieved via token or userinfo request (#9631) Fix bug where…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in server side request forgery or …
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, ci…
Release 1.6.12 Support IPv6 in database DSN (#9937) Don't force specific error_reporting setting Fix compatibility with PHP 8.5 regarding array_first() Remove …
A security vulnerability was discovered in Smarty, a template engine for PHP, which could result in PHP code injection. For the stable distribution (bookworm),…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in denial of service, authorizatio…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service, CLRF injectio…
Multiple vulnerabilties were discovered for smarty3, a widely-used PHP templating engine, which potentially allows an attacker to perform an XSS (e.g JavaScrip…
Moritz Rauch discovered that the Symfony PHP framework implemented persisted remember-me cookies incorrectly, which could result in authentication bypass.
Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to privilege escalation, information disclosure, incorrect validation or…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in incorrect parsing of multipart/f…
It was discovered that there were a number of command-line injection vulnerabilities in Composer, a popular dependency manager for PHP. The 'install', 'status'…
PHP, a widely-used open source general purpose scripting language, is affected by a security problem when parsing certain types of URLs. Due to a code logic er…
Security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in information disclosure or incorrect vali…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in secure cookie bypass, XXE attack…
A security researcher earlier today publicly revealed details and proof-of-concept exploit code for an unpatched, critical zero-day remote code execution vulne…
If you are running an online discussion forum based on vBulletin software, make sure it has been updated to install a newly issued security patch that fixes a …