Checked August 17, 2026 via the GitHub Advisory Database API: all six fake SQLite CVEs rejected by MITRE still show CVSS up to 9.8 as type unreviewed, withdrawn_at null.
54 of 55 advisories from one GitHub account were fabricated, likely by AI. How six fake SQLite CVEs passed MITRE and NVD unchecked, and why scanner hits for them are false positives.
15 formats renamed to .png, then Rails 8.1.3 vs 8.1.3.1 on one attachment: SVG logged 123x45 on the vulnerable build, nothing on the patched one. Plus the matload entry point and the libvips 8.13 floor that stops boot.
Fastjson 1.2.68–1.2.83 is exploited with no AutoType and no gadgets. What gates it: Spring Boot executable fat-JAR, SafeMode off, and Object/Map fields in your DTO.
Russian state actors ran ZimReaper stored XSS in Zimbra Classic UI. What to check before and after updating to 10.1.20: mailbox.log SOAP bursts, ZimbraWeb app passwords, IMAP flips, DNS exfil.
CRA Article 14 reporting starts September 11, 2026 — over a year before the 2027 deadline. Where SBOM, support periods, and the 24-hour warning collide with EOL parts like OpenSSL 3.0 and .NET 8.
WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 are vulnerable to pre-auth RCE via batch-route confusion plus SQLi. Update to 7.0.2/6.9.5 (6.8.6 for 6.8.x), how to block /wp-json/batch/v1, and where to look in REST logs.
Ghost 3.24.0–6.19.0 Content API SQLi leaked Admin API keys and injected ClickFix loaders into posts. Patch to 6.19.1+, rotate keys, and grep post bodies.
Actively exploited unauth RCE (CVSS 10.0) in Joomla JCE ≤2.9.99.4 via profile import, now in CISA KEV. Patch to 2.9.99.7, then hunt rogue profiles and webshells.
Vitest's UI/api WebSocket skips Origin checks (CSWSH), so a malicious page can call saveTestFile and rerun to run code on your dev machine. Fixed in 1.6.1 / 2.1.9 / 3.0.5.