Aggregator
CVE-2026-1247 | seosbg Survey Plugin up to 1.1 on WordPress Setting cross site scripting
CVE-2026-1275 | gbsdeveloper Multi Post Carousel by Category Plugin up to 1.4 on WordPress Shortcode post_slides_shortcode slides cross site scripting
CVE-2026-1313 | eagerterrier MimeTypes Link Icons Plugin up to 3.2.20 on WordPress server-side request forgery
CVE-2026-1278 | ketanmujumdar Mandatory Field Plugin up to 1.6.8 on WordPress Setting cross site scripting
CVE-2026-1378 | suifengtec WP Posts Re-order Plugin up to 1.0 on WordPress Setting cpt_plugin_options cross-site request forgery
CVE-2026-32898 | OpenClaw up to 2026.2.22 reliance on untrusted inputs in a security decision (GHSA-7jx5-9fjg-hp4m / WID-SEC-2026-0542)
CVE-2026-32895 | OpenClaw up to 2026.2.25 Message message_changed authorization (GHSA-v8cg-4474-49v8)
CVE-2026-32897 | OpenClaw up to 2026.2.21 gateway.auth.token key management (GHSA-v6x2-2qvm-6gv8)
CVE-2026-32899 | OpenClaw up to 2026.2.24 authorization (GHSA-rm2p-j3r7-4x4j / WID-SEC-2026-0542)
CVE-2026-32896 | OpenClaw up to 2026.2.20 BlueBubbles Plugin missing authentication (GHSA-5mx2-2mgw-x8rm)
DVRTC: intentionally vulnerable VoIP/WebRTC lab with SIP enumeration, RTP bleed, TURN abuse, and credential cracking exercises
Telnyx PyPI Package With 742,000 downloads Compromised in TeamPCP Supply Chain Attack
The official Telnyx Python SDK on PyPI was compromised this morning as part of an escalating, weeks-long supply chain campaign orchestrated by the threat actor group TeamPCP. Malicious versions 4.87.1 and 4.87.2 of the telnyx package were uploaded to PyPI at 03:51 UTC on March 27, 2026, with the payload executing silently at import time […]
The post Telnyx PyPI Package With 742,000 downloads Compromised in TeamPCP Supply Chain Attack appeared first on Cyber Security News.
Ajax data breach exposed season tickets, supporter bans open to tampering
AFC Ajax, the Dutch football club from Amsterdam, disclosed that an unknown hacker gained access to parts of its IT systems and obtained the email addresses of a few hundred people. The hack exploited vulnerabilities in Ajax’s app and website, including exposed APIs and shared access keys. The club stated that names, email addresses, and dates of birth were accessed for fewer than 20 individuals subject to a stadium ban. An RTL journalist, who was … More →
The post Ajax data breach exposed season tickets, supporter bans open to tampering appeared first on Help Net Security.