· Security Notices
Weekly security digest: 7 September 2026
Security advisories, releases and end-of-life dates for WordPress, Ruby, Rails, SilverStripe, PHP and databases from 1 September 2026 to 7 September 2026.
WordPress vulnerabilities
Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State/Chunk Hash Confusion
- Gravity Forms: affects up to 3.0.2, fixed in 3.0.3
- Severity: CVSS 8.1
- CVE: CVE-2026-19513
- Read the advisory
Vulnerability data from Wordfence Intelligence. Each entry links to its record. Copyright 2012-2026 Defiant Inc. Copyright 1999-2026 The MITRE Corporation. Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
End of life soon
- Rails 8.0 reaches end of life on 7 November 2026 (61 days).
- PostgreSQL 14 reaches end of life on 12 November 2026 (66 days).