Security releaseUmbraco backoffice advisory CVE-2026-41205 — managed clients already patched.Read the advisory
websitesupport.io
Resources

Security alerts

Verified CVE advisories and patch status across Drupal, WordPress, Magento, Shopify, Strapi, Contentful, Umbraco and Webflow.

CriticalScore: 19/25UmbracoCVE-2026-41205

Umbraco — authentication bypass in backoffice

A flaw in the backoffice authentication flow could allow session hijacking on unpatched Umbraco 13/14 instances. Upgrade immediately and rotate admin sessions.

24 Jul 2026
Patched for managed clients
HighScore: 14/25WebflowWF-2026-0619

Webflow — third-party embed script risk

A popular Webflow marketplace app was found injecting unvetted third-party scripts into published sites. Audit embeds and remove the affected app.

19 Jul 2026
Advisory
HighScore: 16/25WordPressWP-2026-0703

WordPress — SQL injection in form plugin

A widely-installed forms plugin shipped an emergency patch for an unauthenticated SQL injection flaw. Update immediately across all sites running it.

15 Jul 2026
Patched for managed clients
MediumScore: 11/25ContentfulCTFL-2026-014

Contentful — overly permissive CMA tokens

Content Management API tokens created before April 2026 may carry broader scopes than intended. Rotate tokens and review app installations.

8 Jul 2026
Advisory
MediumScore: 10/25DrupalSA-CONTRIB-2026-058

Drupal contrib — webform submission exposure

A popular Webform-adjacent module could expose submission data to unauthenticated users under specific display configurations.

1 Jul 2026
Patched for managed clients
LowScore: 7/25ShopifySHOP-2026-142

Shopify — checkout extension data exposure

A checkout UI extension pattern could leak customer email addresses to browser console logs in specific themes. Update the extension.

24 Jun 2026
Advisory
HighScore: 15/25MagentoAPSB26-31

Adobe Commerce — authenticated file upload RCE

An authenticated admin user could upload a crafted file leading to remote code execution. Apply the June security patch and audit admin accounts.

17 Jun 2026
Patched for managed clients
MediumScore: 12/25StrapiCVE-2026-4471

Strapi — GraphQL introspection data leak

Default GraphQL configuration could expose content-type schemas to unauthenticated users, revealing internal data structures.

11 Jun 2026
Mitigation available
LowScore: 6/25WebflowWF-2026-0605

Webflow — form spam via exposed endpoint

Native Webflow forms without CAPTCHA are seeing a wave of automated spam submissions industry-wide. Enable reCAPTCHA and review notification rules.

5 Jun 2026
Advisory
MediumScore: 10/25UmbracoCVE-2026-38220

Umbraco — package installer path traversal

The package installer in Umbraco 12/13 could be tricked into writing files outside the intended directory. Update to the latest patch release.

3 Jun 2026
Patched for managed clients
CriticalScore: 20/25DrupalSA-CORE-2026-008

Drupal core — access bypass

Unauthenticated access bypass affecting Drupal 10.3–11.1. Patch to 10.3.14 / 10.4.6 / 11.1.4 immediately.

30 May 2026
Patched for managed clients
HighScore: 15/25WordPressWP-2026-0512

WordPress — popular plugin RCE

Two widely-used plugins shipped urgent fixes. Update affected plugins across all instances now.

19 May 2026
Patched for managed clients
HighScore: 16/25MagentoAPSB26-22

Adobe Commerce — XSS in admin

Stored XSS in the admin panel. Apply the latest Adobe Commerce security patch and rotate admin sessions.

12 May 2026
Mitigation available
MediumScore: 11/25DrupalSA-CONTRIB-2026-041

Drupal contrib — Views access

A contributed module exposes unpublished content via a Views endpoint under specific configs.

4 May 2026
Patched for managed clients
MediumScore: 10/25StrapiCVE-2026-3318

Strapi — privilege escalation

An authenticated user could escalate permissions via the admin API. Upgrade to the latest v5 patch.

27 Apr 2026
Patched for managed clients
LowScore: 6/25ShopifySHOP-2026-118

Shopify app — token leakage

A third-party app could leak storefront tokens in logs. Rotate tokens and update the app.

20 Apr 2026
Advisory

Never patch late again

Managed clients are patched within SLA — typically the same day a critical advisory is published, often before it's public.

Stay ahead of the next release

Security alerts, platform updates and industry analysis — straight to your inbox.

We respect your privacy and only send essential updates.