♡Follow0 Critical CVEs iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days; CISA Adds to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity vulnerabilities affecting iCagenda and Balbooa Forms extensions for Joomla to… ACSC arbitrary file upload Australia Balbooa Forms July 13, 2026
♡Follow0 Cyber Products WavePlayer WordPress Plugin A WordPress plugin for audio playback, targeted in a global CMS exploitation campaign for web shell deployment. plugin vulnerability WavePlayer WordPress July 13, 2026
♡Follow0 Critical CVEs CVE-2025-12057: WavePlayer WordPress Plugin Vulnerability A vulnerability in the WavePlayer WordPress plugin exploited in a global CMS campaign for web shell deployment. CMS CVE-2025-12057 WavePlayer web shell July 10, 2026