Security alerts
Verified CVE advisories and patch status across Drupal, WordPress, Magento, Shopify, Strapi, Contentful, Umbraco and Webflow.
Umbraco — authentication bypass in backoffice
A flaw in the backoffice authentication flow could allow session hijacking on unpatched Umbraco 13/14 instances. Upgrade immediately and rotate admin sessions.
Webflow — third-party embed script risk
A popular Webflow marketplace app was found injecting unvetted third-party scripts into published sites. Audit embeds and remove the affected app.
WordPress — SQL injection in form plugin
A widely-installed forms plugin shipped an emergency patch for an unauthenticated SQL injection flaw. Update immediately across all sites running it.
Contentful — overly permissive CMA tokens
Content Management API tokens created before April 2026 may carry broader scopes than intended. Rotate tokens and review app installations.
Drupal contrib — webform submission exposure
A popular Webform-adjacent module could expose submission data to unauthenticated users under specific display configurations.
Shopify — checkout extension data exposure
A checkout UI extension pattern could leak customer email addresses to browser console logs in specific themes. Update the extension.
Adobe Commerce — authenticated file upload RCE
An authenticated admin user could upload a crafted file leading to remote code execution. Apply the June security patch and audit admin accounts.
Strapi — GraphQL introspection data leak
Default GraphQL configuration could expose content-type schemas to unauthenticated users, revealing internal data structures.
Webflow — form spam via exposed endpoint
Native Webflow forms without CAPTCHA are seeing a wave of automated spam submissions industry-wide. Enable reCAPTCHA and review notification rules.
Umbraco — package installer path traversal
The package installer in Umbraco 12/13 could be tricked into writing files outside the intended directory. Update to the latest patch release.
Drupal core — access bypass
Unauthenticated access bypass affecting Drupal 10.3–11.1. Patch to 10.3.14 / 10.4.6 / 11.1.4 immediately.
WordPress — popular plugin RCE
Two widely-used plugins shipped urgent fixes. Update affected plugins across all instances now.
Adobe Commerce — XSS in admin
Stored XSS in the admin panel. Apply the latest Adobe Commerce security patch and rotate admin sessions.
Drupal contrib — Views access
A contributed module exposes unpublished content via a Views endpoint under specific configs.
Strapi — privilege escalation
An authenticated user could escalate permissions via the admin API. Upgrade to the latest v5 patch.
Shopify app — token leakage
A third-party app could leak storefront tokens in logs. Rotate tokens and update the app.
Never patch late again
Managed clients are patched within SLA — typically the same day a critical advisory is published, often before it's public.
Stay ahead of the next release
Security alerts, platform updates and industry analysis — straight to your inbox.