I wanted a convenient place to reference the latest WordPress and Drupal Security Advisories, so I added the WP RSS Aggregator and then added both the WordPress Security Advisories and Drupal Security Advisories RSS feeds.
WordPress Security Advisories
- WP23
- WordPress 6.9.2 Release
- Dropping security updates for WordPress versions 4.1 through 4.6
- Secure Custom Fields
- WP Engine Reprieve
- 4053440 - Securely opening Microsoft Office documents that contain Dynamic Data Exchange (DDE) fields - Version: 3.0
- 4056318 - Guidance for securing AD DS account used by Azure AD Connect for directory synchronization - Version: 1.0
- 4038556 - Guidance for securing applications that host the WebBrowser Control - Version: 1.0
- 4033453 - Vulnerability in Azure AD Connect Could Allow Elevation of Privilege - Version: 1.0
- 4025685 - Guidance related to June 2017 security update release - Version: 1.0
Drupal Security Advisories
- Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
- Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
- Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
- Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
- Drupal core - Critical - PHP object injection - SA-CORE-2026-005
- Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
- Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003
- Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002
- Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001
- Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008
- 4053440 - Securely opening Microsoft Office documents that contain Dynamic Data Exchange (DDE) fields - Version: 3.0
- 4056318 - Guidance for securing AD DS account used by Azure AD Connect for directory synchronization - Version: 1.0
- 4038556 - Guidance for securing applications that host the WebBrowser Control - Version: 1.0
- 4033453 - Vulnerability in Azure AD Connect Could Allow Elevation of Privilege - Version: 1.0
- 4025685 - Guidance related to June 2017 security update release - Version: 1.0
Microsoft Security Advisories
- Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
- Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
- Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
- Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
- Drupal core - Critical - PHP object injection - SA-CORE-2026-005
- WP23
- Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
- Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003
- Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002
- Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001
- WordPress 6.9.2 Release
- Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008
- Dropping security updates for WordPress versions 4.1 through 4.6
- Secure Custom Fields
- WP Engine Reprieve
Other Links:
Cold Fusion Security Advisories
Java Security Advisories
PHP Security Advisories
MySQL Security Advisories