WhisperX tag archive

#CMS vulnerability

This page collects WhisperX intelligence signals tagged #CMS vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-01 08:26:58 · GitHub Issues

1. Magix CMS 4 Exposed Installer Allows Unauthenticated Admin Takeover

A critical security flaw in Magix CMS 4 leaves the software's installation workflow fully accessible after deployment, enabling any unauthenticated attacker to completely hijack the website. The vulnerability stems from the installer entry point failing to properly block access once the CMS is configured, allowing remo...

The Lab · 2026-05-10 22:01:42 · Mastodon:mastodon.social:#infosec

2. JDownloader Website Hijacked: Malicious Installers Served via CMS Exploit

JDownloader's official website was compromised through a CMS vulnerability, allowing threat actors to replace legitimate Windows and Linux installers with malware-laden versions. The attack window spans May 6–7, 2026, during which users who downloaded the Windows Alternative Installer or Linux shell script and executed...