cms-security
Safeguard articles tagged "cms-security" — guides, analysis, and best practices for software supply chain and application security.
7 articles
A Critical SQL Injection in Drupal Core's Database Abstraction Layer Is Being Actively Exploited
CVE-2026-9082 hits the shared database abstraction API every Drupal module and query routes through, confirmed exploited just two days after Drupal's own security advisory.
Three Kentico Xperience CVEs Chain Into Pre-Auth RCE Through One Component
Two authentication bypasses and a path traversal bug all target Kentico Xperience's Staging Sync Server, chaining into a documented pre-authentication remote code execution path.
Craft CMS's Perfect-Score CVE Was the Fix Behind an Older Fix
CVE-2025-32432 scores a maximum 10.0 and is confirmed exploited — and NVD's own record calls it an additional fix for a 2023 vulnerability that wasn't fully closed the first time.
Two WordPress CVEs, and NVD Says They're the Same Attack Chain
WordPress core's CVE-2026-63030 explicitly references CVE-2026-60137 in its own NVD description — a documented exploitation chain, not two coincidentally similar bugs.
Four CMS Plugins, Four Vendors, the Same Unrestricted Upload Bug in Three Days
Four Joomla extensions from unrelated developers had unauthenticated file upload vulnerabilities confirmed exploited within a three-day window in July 2026, every one scoring CVSS 9.8.
Drupal module vulnerability trends
Contributed modules drive most Drupal risk today. Here's what the advisory trends show — and how reachability analysis changes triage.
Security Plugins for CMS and App Platforms: What They Actually Do
A security plugin can harden a CMS meaningfully, but it can't fix a vulnerable core install or a poorly coded theme — it's a layer, not a replacement for patching.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.