← All articles

web security

6 articles

CVEweb securitysupply chainremediationdevelopment

CVE-2026-45618: Your Template Engine Runs Arbitrary Code. CVSS 10.

LiquidJS, a templating library with 7 million monthly downloads, lets attackers run any code on your server through a crafted template string. No login required. Public exploit available.

Jun 4, 2026
CVEweb securitysmall businessremediation

CVE-2026-41940: Two Characters Give an Attacker Root on Your Hosting Panel

An unauthenticated CRLF injection in cPanel gives full root control. If your website runs on shared hosting, your host might already be compromised. CVSS 9.8.

May 31, 2026
AIvibe codingweb securitydevelopment

Vibe Coding Is a Security Disaster and Nobody Cares

380,000 AI-built apps deployed with zero security review. 45% of AI-generated code has OWASP Top 10 vulnerabilities. An AI social network leaked its entire database in 3 days. But sure, ship it.

May 25, 2026
CVEweb securityremediationsmall businessCISA KEVDrupal

CVE-2026-9082: If Your Website Runs Drupal on PostgreSQL, It's Leaking Data

Anonymous SQL injection in Drupal core. No login required. On CISA KEV. Mass scanning started within days. If you run Drupal on PostgreSQL, patch right now or take it offline.

May 21, 2026
CVEweb securitysmall businessCISA KEV

Your Next.js Auth Middleware Was Decorative This Whole Time

Set one HTTP header and skip all middleware. Authentication, authorization, rate limiting, all of it. CVE-2025-29927. Confirmed exploitation in the wild. If you run Next.js, update now.

May 20, 2026
WordPressweb securitysupply chain

Your WordPress Site Is Probably Already Compromised

30-40% of WordPress sites are running plugins with known vulnerabilities. A supply chain attack just backdoored 400,000 sites through trusted plugin updates. If you run WordPress, read this.

May 4, 2026