Zero-click RCE in Avada leaves million sites exposed
A 9.8-rated flaw chain in the Avada WordPress theme lets unauthenticated attackers run PHP code.
5 results for “php”
A 9.8-rated flaw chain in the Avada WordPress theme lets unauthenticated attackers run PHP code.
A critical PHP object injection vulnerability in MaxSite CMS allows unauthenticated attackers to execute arbitrary code via a malicious cookie.
A critical remote code execution vulnerability in MaxSite CMS allows unauthenticated attackers to inject malicious PHP code into configuration files.
A critical vulnerability in Twig versions 3.9.0 through 3.25.0 allows sandboxed templates to bypass security policy enforcement.
A critical vulnerability in Twig versions prior to 3.26.0 allows attackers to inject arbitrary PHP code via crafted template names in {% use %} tags.