News Security CVE-2026-19513: Gravity Forms unauthenticated file upload risk and what site owners should do September 2, 2026 by Alex Mira | Leave a Comment CVE-2026-19513 affects Gravity Forms ≤ 3.0.2, allowing unauthenticated file writes under specific conditions. Update to 3.0.3+ and verify upload directory behavior, especially on NGINX. Read more » Arbitrary file upload CVE-2026-19513 Gravity Forms NGINX Plugin vulnerability Remote code execution risk WordPress security
News CVE-2026-42945: NGINX rewrite-module bug tied to PCRE captures and “?” in replacements May 13, 2026 / May 13, 2026 by Alex Mira | Leave a Comment CVE-2026-42945 affects NGINX’s rewrite module under specific PCRE capture and replacement patterns, causing a heap overflow and worker restarts; code execution may be possible if ASLR is disabled. Version and patch details are not yet clear. Read more » CVE-2026-42945 NGINX PCRE Reverse Proxy Security advisory vulnerability Web Security