⤷ Title: Critical PrestaShop Flaw Allows Hijacking via “Contact Us” Form
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 02:11:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Back_office Hijacking #Cross_Site Scripting #CVE_2026_44212 #e_commerce security #infosec #Patch Alert #PHP Security #PrestaShop #Stored XSS #Web Security #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 02:11:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Back_office Hijacking #Cross_Site Scripting #CVE_2026_44212 #e_commerce security #infosec #Patch Alert #PHP Security #PrestaShop #Stored XSS #Web Security #XSS
Daily CyberSecurity
Critical PrestaShop Flaw Allows Hijacking via "Contact Us" Form
Urgent: PrestaShop patches a 9.3 severity XSS flaw (CVE-2026-44212) that allows unauthenticated attackers to hijack your store's back office. Update now!
⤷ Title: Critical PHP SOAP Vulnerabilities Put Web Applications at Risk of Remote Code Execution
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Tue, 12 May 2026 09:55:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_application_security #remote_code_execution #application_security #php_security
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Tue, 12 May 2026 09:55:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_application_security #remote_code_execution #application_security #php_security
Medium
Critical PHP SOAP Vulnerabilities Put Web Applications at Risk of Remote Code Execution
Security researchers have disclosed critical vulnerabilities in PHP’s SOAP extension that could allow attackers to execute arbitrary code…
⤷ Title: Explorando Remote Code Execution (RCE) no WordPress
════════════════════════
𐀪 Author: Link
════════════════════════
ⴵ Time: Tue, 12 May 2026 15:22:36 GMT
════════════════════════
⌗ Tags: #wordpress #php #pentesting #cybersecurity #rce
════════════════════════
𐀪 Author: Link
════════════════════════
ⴵ Time: Tue, 12 May 2026 15:22:36 GMT
════════════════════════
⌗ Tags: #wordpress #php #pentesting #cybersecurity #rce
Medium
Explorando Remote Code Execution (RCE) no WordPress
Hoje executaremos um código malicioso no servidor WordPress. Para isso, temos como pré-requisito:
⤷ Title: Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
Daily CyberSecurity
Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
Composer CVE-2026-45793 leaks GitHub tokens into CI/CD logs due to a validation error. Update to version 2.9.8 now and audit your GitHub Action logs.
⤷ Title: Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
Daily CyberSecurity
Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
Socket exposes a clever cross-ecosystem supply chain attack targeting PHP packages by hiding a malicious JS postinstall backdoor inside package.json.
⤷ Title: Supply Chain Storm: Over 700 Laravel Lang Versions Poisoned with Malicious RCE Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:24:14 +0000
════════════════════════
⌗ Tags: #Malware #App_Bound Encryption #Composer Backdoor #Credential Harvesting #Cyber Security #DevOps Security #flipboxstudio #info_stealer #Laravel Lang #PHP RCE #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:24:14 +0000
════════════════════════
⌗ Tags: #Malware #App_Bound Encryption #Composer Backdoor #Credential Harvesting #Cyber Security #DevOps Security #flipboxstudio #info_stealer #Laravel Lang #PHP RCE #supply chain attack
Daily CyberSecurity
Supply Chain Storm: Over 700 Laravel Lang Versions Poisoned with Malicious RCE Backdoor
DevOps Alert: Over 700 laravel-lang localization package versions have been backdoored with a cross-platform 17-collector info-stealer. Audit your logs.
⤷ Title: Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:17:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ceselector #Content Element Selector #CVE_2026_46725 #Cyber Security #infosec #Insecure Deserialization #Patch Alert #PHP Object Injection #Remote Code Execution #TYPO3 Extension #TYPO3_EXT_SA_2026_013
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:17:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ceselector #Content Element Selector #CVE_2026_46725 #Cyber Security #infosec #Insecure Deserialization #Patch Alert #PHP Object Injection #Remote Code Execution #TYPO3 Extension #TYPO3_EXT_SA_2026_013
Daily CyberSecurity
Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE
Urgent: TYPO3 patches a critical 9.2 CVSS flaw (CVE-2026-46725) in Content Element Selector plugin. Unauthenticated attackers can achieve full server RCE.
⤷ Title: Dual Sandbox Bypasses Threaten PHP Applications
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 01:30:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_46633 #CVE_2026_46640 #PHP Security #Remote Code Execution #Sandbox Bypass #Twig Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 01:30:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_46633 #CVE_2026_46640 #PHP Security #Remote Code Execution #Sandbox Bypass #Twig Engine
Daily CyberSecurity
Dual Sandbox Bypasses Threaten PHP Applications
Twig project maintainers patched critical Twig RCE flaws allowing arbitrary code execution via sandbox bypasses. Update to 3.26.0.
⤷ Title: Four-Way PHP Domino-Fall: Unchecked Input to Full Root Compromise
════════════════════════
𐀪 Author: Xia0checkmate
════════════════════════
ⴵ Time: Fri, 29 May 2026 17:39:38 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #critical_thinking #bug_bounty_writeup #source_code_review #php
════════════════════════
𐀪 Author: Xia0checkmate
════════════════════════
ⴵ Time: Fri, 29 May 2026 17:39:38 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #critical_thinking #bug_bounty_writeup #source_code_review #php
Medium
Four-Way PHP Domino-Fall: Unchecked Input to Full Root Compromise
A single, seemingly innocent HTTP endpoint can form a critical business-impact chain when multiple structural PHP weaknesses are stitched…
⤷ Title: exfiltration using numeric-only outputs
════════════════════════
𐀪 Author: Bartosz
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 07:50:37 GMT
════════════════════════
⌗ Tags: #pentesting #infosec #hacking #php
════════════════════════
𐀪 Author: Bartosz
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 07:50:37 GMT
════════════════════════
⌗ Tags: #pentesting #infosec #hacking #php
Medium
exfiltration using numeric-only outputs
after identifying a code-injection vulnerability, we always want to look around inside the compromised system. most of the time, we can…
⤷ Title: PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 01:33:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_45034 #cybersecurity #Exploit #php #PhpSpreadsheet #rce
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 01:33:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_45034 #cybersecurity #Exploit #php #PhpSpreadsheet #rce
Daily CyberSecurity
PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
A critical PhpSpreadsheet RCE vulnerability impacts 312 million users. Learn how the CVE-2026-45034 exploit bypasses patches and triggers code execution.
⤷ Title: Part 3/3: Exploiting phpinfo() — Turning Information into Compromise
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Sun, 14 Jun 2026 19:25:11 GMT
════════════════════════
⌗ Tags: #php #penetration_testing #bug_bounty #information_leak #phpinfo
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Sun, 14 Jun 2026 19:25:11 GMT
════════════════════════
⌗ Tags: #php #penetration_testing #bug_bounty #information_leak #phpinfo
Medium
🎓 Part 3/3: Exploiting phpinfo() — Turning Information into Compromise 🎓
Finding a phpinfo() file is just the beginning. The real value comes from analyzing its contents and using that data to advance your…
⤷ Title: CodeIgniter Vulnerability Enables Arbitrary Code Execution (CVSS 9.8)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 00:54:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CodeIgniter #CVE_2026_48062 #File Upload Vulnerability #PHP Security #rce
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 00:54:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CodeIgniter #CVE_2026_48062 #File Upload Vulnerability #PHP Security #rce
Daily CyberSecurity
CodeIgniter Vulnerability Enables Arbitrary Code Execution (CVSS 9.8)
A critical CodeIgniter vulnerability (CVE-2026-48062, CVSS 9.8) lets attackers bypass upload checks and trigger arbitrary code execution. Update now.
⤷ Title: Analysis CVE-2026–48907 — Joomla JCE
════════════════════════
𐀪 Author: xpl0dec
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 13:11:53 GMT
════════════════════════
⌗ Tags: #php #hacking #proof_of_concept #vulnerability #cybersecurity
════════════════════════
𐀪 Author: xpl0dec
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 13:11:53 GMT
════════════════════════
⌗ Tags: #php #hacking #proof_of_concept #vulnerability #cybersecurity
Medium
Analysis CVE-2026–48907 — Joomla JCE
Sekitar beberapa hari lalu, terdapat kerentanan pada extension JCE(Joomla Content Editor) yang digunakan CMS joomla untuk menggantikan…
⤷ Title: Secure by Design: Implementing Advanced Security in Laravel
════════════════════════
𐀪 Author: Hector Canovas
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 06:29:38 GMT
════════════════════════
⌗ Tags: #cybersecurity #sql_injection #php #software_architecture #laravel
════════════════════════
𐀪 Author: Hector Canovas
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 06:29:38 GMT
════════════════════════
⌗ Tags: #cybersecurity #sql_injection #php #software_architecture #laravel
Medium
Secure by Design: Implementing Advanced Security in Laravel
Strengthen Your Laravel Fortress Against Modern Threats
⤷ Title: PHP Patches Remote DoS Flaw CVE-2026-12184 and an OpenSSL Memory Corruption Bug
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 02:41:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12184 #CVE_2026_14355 #Denial of Service #memory corruption #php #PHP_FPM #Remote DoS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 02:41:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12184 #CVE_2026_14355 #Denial of Service #memory corruption #php #PHP_FPM #Remote DoS
Daily CyberSecurity
PHP Patches Remote DoS Flaw CVE-2026-12184 and an OpenSSL Memory Corruption Bug
TL;DR The PHP team fixed two flaws, including a PHP remote DoS that can crash a whole PHP-FPM pool. CVE-2026-12184 (CVSS 8.2) triggers on a failed TLS handshake with a remote server. A second bug,…
⤷ Title: CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 13:30:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_59946 #CVE_2026_59947 #CVE_2026_59948 #Path Traversal #PHP Composer #Supply Chain
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 13:30:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_59946 #CVE_2026_59947 #CVE_2026_59948 #Path Traversal #PHP Composer #Supply Chain
Daily CyberSecurity
CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context
TL;DR PHP Composer, the main dependency manager for the language, patched three security flaws. The most serious, CVE-2026-59948, is an arbitrary file write rated CVSS 7.0. A malicious package can…
⤷ Title: Hwat Hell Machine Hacking | Achieving Reverse Shell and Capturing the Flags
════════════════════════
𐀪 Author: ABDUL AHAD
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 16:39:11 GMT
════════════════════════
⌗ Tags: #hacking #web_enumeration #ctf #php_reverse_shell #sql_injection
════════════════════════
𐀪 Author: ABDUL AHAD
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 16:39:11 GMT
════════════════════════
⌗ Tags: #hacking #web_enumeration #ctf #php_reverse_shell #sql_injection
Medium
Hwat Hell Machine Hacking | Achieving Reverse Shell and Capturing the Flags
hwats hell machine
⤷ Title: A Crypto Zero-Day Huntress
════════════════════════
𐀪 Author: CypherBlush™
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 22:27:29 GMT
════════════════════════
⌗ Tags: #infosec #women_in_tech #php #defi #cryptocurrency
════════════════════════
𐀪 Author: CypherBlush™
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 22:27:29 GMT
════════════════════════
⌗ Tags: #infosec #women_in_tech #php #defi #cryptocurrency
Medium
A Crypto Zero-Day Huntress
Securing Crypto Wallet Architecture
⤷ Title: Source Code Review: PHP | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 11:01:08 GMT
════════════════════════
⌗ Tags: #tryhackme #php #cybersecurity #red_team
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 11:01:08 GMT
════════════════════════
⌗ Tags: #tryhackme #php #cybersecurity #red_team
Medium
Source Code Review: PHP | TryHackMe
Learn the basics of source code review for PHP.