YesWeHack discloses critical RCE in Joomla Content Editor extension
The flaw allows attackers to upload and execute arbitrary PHP code without authentication. It was fixed in version 2.9.99.5.
See the latest news and media coverage for YesWeHack. We track all announcements, press releases, and industry mentions in real time, all in one place.
Offensive security and exposure management platform
yeswehack.comLast updated
In short: YesWeHack expanded its offensive security platform with new pentesting services, AI-driven triage, and critical vulnerability disclosures.
The flaw allows attackers to upload and execute arbitrary PHP code without authentication. It was fixed in version 2.9.99.5.
CVE-2026-9082 affects Drupal's entity query subsystem when using PostgreSQL backend, allowing remote unauthenticated SQL injection.
Users access all programs, view details, and add assets directly in Caido. It enables seamless bug bounty hunting.
Compromised maintainer published malicious versions 1.14.1 and 0.30.4 injecting RAT dropper. Users should downgrade immediately.
The second, Continuous Pentesting, consists of security audits driven by human expertise, supposed to guarantee zero false positives. These announcements fit into a movement...
YesWeHack extends its positioning beyond bug bounty and launches two new intrusion testing offers, the Autonomous Pentest and the Continuous Pentest, to cover...
DECODING - The cybersecurity platform, which will blow out its ten candles on October 14, has just signed an important contract to help protect the...
YesWeHack, the collaborative platform for security testing and vulnerability management, becomes the reference provider for the European Commission for programs...
Track YesWeHack and your other target companies to get real-time alerts and weekly summaries delivered straight to your inbox.
Browse news for competitors to YesWeHack and other trending companies.