#cms,


ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

Sep 26, 2026 // 00:58

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through […]

Australia warns of global campaign targeting vulnerable CMS platforms

Jul 12, 2026 // 16:17

The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. The government agency […]

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

May 25, 2026 // 19:10

Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. […]

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

May 24, 2026 // 18:57

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. The […]

MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks

May 6, 2026 // 00:48

Threat actors are actively exploiting a critical security flaw impacting an open-source content management system (CMS) known as MetInfo, according to new findings from VulnCheck. […]

CISA: Apple, Craft CMS, Laravel Flaws in KEV. Patch by 4/3/26 Mandated.

Mar 21, 2026 // 11:34

On Friday, the U.S. agency responsible for cybersecurity, CISA, added five security weaknesses in products from Apple, Craft CMS, and Laravel Livewire to its list […]