Safeguard
Tag

cms-security

Safeguard articles tagged "cms-security" — guides, analysis, and best practices for software supply chain and application security.

7 articles

Vulnerability Analysis

A Critical SQL Injection in Drupal Core's Database Abstraction Layer Is Being Actively Exploited

CVE-2026-9082 hits the shared database abstraction API every Drupal module and query routes through, confirmed exploited just two days after Drupal's own security advisory.

Sep 16, 20265 min read
Vulnerability Analysis

Three Kentico Xperience CVEs Chain Into Pre-Auth RCE Through One Component

Two authentication bypasses and a path traversal bug all target Kentico Xperience's Staging Sync Server, chaining into a documented pre-authentication remote code execution path.

Sep 16, 20265 min read
Vulnerability Analysis

Craft CMS's Perfect-Score CVE Was the Fix Behind an Older Fix

CVE-2025-32432 scores a maximum 10.0 and is confirmed exploited — and NVD's own record calls it an additional fix for a 2023 vulnerability that wasn't fully closed the first time.

Sep 16, 20265 min read
Vulnerability Analysis

Two WordPress CVEs, and NVD Says They're the Same Attack Chain

WordPress core's CVE-2026-63030 explicitly references CVE-2026-60137 in its own NVD description — a documented exploitation chain, not two coincidentally similar bugs.

Sep 16, 20264 min read
Vulnerability Analysis

Four CMS Plugins, Four Vendors, the Same Unrestricted Upload Bug in Three Days

Four Joomla extensions from unrelated developers had unauthenticated file upload vulnerabilities confirmed exploited within a three-day window in July 2026, every one scoring CVSS 9.8.

Sep 16, 20265 min read
Open Source Security

Drupal module vulnerability trends

Contributed modules drive most Drupal risk today. Here's what the advisory trends show — and how reachability analysis changes triage.

Jul 16, 20266 min read
AppSec

Security Plugins for CMS and App Platforms: What They Actually Do

A security plugin can harden a CMS meaningfully, but it can't fix a vulnerable core install or a poorly coded theme — it's a layer, not a replacement for patching.

May 16, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.