Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
ZAST engine has identified and verified CVE-2026-1829 in Content Visibility for Divi Builder 4.01, along with one additional verified vulnerability in the same plugin.
Project page: https://wordpress.org/plugins/content-visibility-for-divi-builder/ Project footprint: 2,000+ active installations on WordPress.org.
The critical issue is a code-execution path where user-controlled visibility expressions reach eval() through multiple application features. This is a representative example of why security teams need autonomous verification: dangerous APIs alone do not define risk. Reachability, privilege boundaries, and runtime behavior do.
ZAST.AI promotes findings into reports only after successful PoC validation, which supports a zero-false-positive operating model and helps enterprise teams prioritize remediation on verified issues.
Full report: https://blog.zast.ai/vulnerability%20research/ai%20security/Auditing-Content-Visibility-for-Divi-Builder/
@wordfence @WordPress@mastodon.world @wordpress@lemmy.world
#ApplicationSecurity #WordPressSecurity #AppSec #VulnerabilityResearch #AIForSecurity
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
#RegPwn - eine Schwachstelle in Windows, die Nutzern eine Rechteausweitung per Registry ermöglicht, wurde still im März 2026 per Update gepatcht.
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Overview
- Kubernetes
- ingress-nginx
Description
Statistics
- 3 Posts
- 1 Interaction
Overview
- Nefteprodukttekhnika LLC
- BUK TS-G Gas Station Automation System
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- siyuan-note
- siyuan
Description
Statistics
- 1 Post
Fediverse
⚠️ CVE-2026-32767: SiYuan (<3.6.1) has a CRITICAL SQL injection flaw in /api/search/fullTextSearchBlock. Any authenticated user can run SQL, risking full data compromise. Upgrade to 3.6.1+ ASAP. https://radar.offseq.com/threat/cve-2026-32767-cwe-89-improper-neutralization-of-s-8a5766fd #OffSeq #SiYuan #SQLInjection #Vuln
Overview
- Red Hat
- Red Hat Enterprise Linux 10
- libxml2
Description
Statistics
- 1 Post
Overview
- Xerte
- Xerte Online Toolkits
Description
Statistics
- 1 Post
Fediverse
🔴 CRITICAL: CVE-2026-32985 in Xerte Online Toolkits ≤3.14 lets attackers upload PHP via import.php and gain RCE — no auth needed! Patch ASAP or restrict access, disable PHP in user dirs. Details: https://radar.offseq.com/threat/cve-2026-32985-cwe-306-missing-authentication-for--04629a96 #OffSeq #CVE202632985 #infosec #RCE
Overview
- WWBN
- AVideo-Encoder
Description
Statistics
- 1 Post
Fediverse
🚨 CVE-2026-33024: CRITICAL SSRF in WWBN AVideo-Encoder <8.0. Public API allows blind SSRF, risking internal/cloud data exposure. Upgrade to v8.0 or restrict outbound traffic now! https://radar.offseq.com/threat/cve-2026-33024-cwe-918-server-side-request-forgery-82e88a08 #OffSeq #SSRF #Vulnerability #InfoSec