Invicti Platform Security checks and Runtime SCA findings
RSS feedTrack new security checks, vulnerability detection capabilities, and Runtime SCA findings introduced in each Invicti Platform on-demand release. Updates include enhanced detection methods, CVE coverage, and improvements to vulnerability identification.
2026
Security checks, vulnerability database updates, and Runtime SCA enhancements released in 2026.
Release 20260310
Release date: 11 March 2026
Version: 25.12.12
Security checks
- Updated the vulnerability database (VDB) to version 20260310
- Improved technology detection
- Updated severity ratings for Chamilo versions 1.10.0, 1.10.2, 1.10.4, 1.10.6, 1.10.8, 1.11.26, 1.8.6.1, 1.8.8.3, 1.9.0, 1.9.10, 1.9.10.2, 1.9.10.4, 1.9.6, 1.9.6.1, 1.9.8, 1.9.8.1, 1.9.8.2 from High to Critical
- Updated severity rating for Chamilo version 1.11.24 from Medium to Critical
- Updated severity ratings for Craft CMS versions 4.15.6.2, 4.16.17, 4.16.18, 4.16.19, 4.4.14, 4.5.6.1, 5.6.16, 5.7.1.1, 5.8.21, 5.8.22, 5.8.23 from High to Critical
- Updated severity ratings for DotCMS versions 22.03, 22.03.2, 22.03.4, 22.03.5, 22.03.6, 22.03.7, 22.03.8, 22.03.9, 22.03.10, 22.03.11, 22.03.12, 22.03.13, 22.03.14, 22.03.15, 23.01.1, 23.01.2, 23.01.3, 23.01.4, 23.01.5, 23.01.6, 23.01.7, 23.01.8, 23.01.9, 23.01.10, 23.01.11, 23.01.12, 23.01.13, 23.01.14, 23.01.15, 23.01.16, 23.01.17, 23.10.24.0 from Medium to Critical
- Updated severity ratings for EspoCRM versions 2.6.0, 2.7.0, 2.7.1, 2.7.2, 2.8.0, 2.8.1, 2.9.0, 2.9.1, 2.9.2, 3.0.0, 3.0.1, 3.1.0, 3.1.1, 3.2.0, 3.2.1, 3.2.2, 3.3.0, 3.4.0, 3.4.1, 3.4.2, 3.5.0, 3.5.1, 3.5.2, 3.6.0, 3.6.1, 3.6.2, 3.7.0, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.8.0, 3.9.0, 3.9.1, 3.9.2, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, 4.1.6, 4.2.0, 4.2.1, 4.2.2, 4.2.3, 4.2.4, 4.2.5, 4.2.6, 4.2.7, 4.3.0, 4.3.1, 4.4.0, 4.4.1, 4.5.0, 4.5.1, 4.6.0, 4.7.0, 4.7.1, 4.7.2, 4.8.0, 4.8.1, 4.8.2, 4.8.3, 4.8.4, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.1.0, 5.1.1, 5.1.2, 5.2.0, 5.2.1, 5.2.2, 5.2.3, 5.2.4, 5.2.5, 5.3.0, 5.3.1, 5.3.2, 5.3.3, 5.3.4, 5.3.5, 5.3.6, 5.4.0, 5.4.1, 5.4.2, 5.4.3, 5.4.4, 5.4.5, 5.5.0, 5.5.1, 5.5.2, 5.5.3, 5.5.4, 5.5.5, 5.5.6, 5.6.0, 5.6.1, 5.6.2, 5.6.3, 5.6.4, 5.6.5, 5.6.6, 5.6.7, 5.6.8, 5.6.9, 5.6.10, 5.6.11, 5.6.12, 5.6.13, 5.6.14, 5.7.0, 5.7.1, 5.7.2, 5.7.3, 5.7.4, 5.7.5, 5.7.6, 5.7.7, 5.7.8, 5.7.9, 5.7.10, 5.7.11, 5.8.0, 5.8.1, 5.8.2, 5.8.3, 5.8.4, 5.8.5 from High to Critical
- Updated severity ratings for osCommerce versions 1.0.6.0, 1.0.7.0, 1.0.7.1, 1.0.7.2, 1.0.7.3, 1.0.7.4, 1.0.7.5, 1.0.7.6, 1.0.7.7, 1.0.7.8, 1.0.7.9, 1.1, 1.11, 1.12, 1.13, 2.3, 2.3.1, 2.3.2, 2.3.3, 2.3.3.1, 2.3.3.2, 2.3.3.3, 2.3.3.4, 2.3.4 from Medium to High
- Added vulnerability detection for Chamilo:
- Critical: CVE-2025-50187, CVE-2025-50190, CVE-2025-50192, CVE-2025-50199, CVE-2025-52998
- High: CVE-2024-47886, CVE-2025-50188, CVE-2025-50189, CVE-2025-50191, CVE-2025-50193, CVE-2025-50194, CVE-2025-50195, CVE-2025-50196, CVE-2025-50197, CVE-2025-52469, CVE-2025-52482
- Medium: CVE-2024-50337, CVE-2025-50186, CVE-2025-50198, CVE-2025-52468, CVE-2025-52470, CVE-2025-52475, CVE-2025-52476, CVE-2025-52563, CVE-2025-52564
- Added vulnerability detection for Craft CMS:
- Critical: CVE-2026-28697, CVE-2026-28783
- High: CVE-2026-28695, CVE-2026-28696, CVE-2026-28784
- Medium: CVE-2026-27129, CVE-2026-28781, CVE-2026-28782, CVE-2026-29069
- Added vulnerability detection for DOMPurify:
- Medium: CVE-2025-15599, CVE-2026-0540
- Added vulnerability detection for Django:
- High: CVE-2026-25673
- Low: CVE-2026-25674
- Added vulnerability detection for DotCMS:
- Critical: CVE-2025-11165
- Added vulnerability detection for EspoCRM:
- Critical: CVE-2020-37094
- Added vulnerability detection for Jetty:
- High: CVE-2026-1605
- Medium: CVE-2025-11143
- Added vulnerability detection for MediaWiki:
- Medium: CVE-2025-61645
- Added vulnerability detection for Moodle:
- High: CVE-2025-67847
- Added vulnerability detection for Underscore.js:
- High: CVE-2026-27601
- Added vulnerability detection for Werkzeug:
- Medium: CVE-2026-27199
- Added vulnerability detection for XWikiplatform:
- High: CVE-2025-55749
- Added vulnerability detection for osCommerce:
- Added vulnerability detection for phpMyFAQ:
- High: CVE-2026-27836
Release 20260303
Release date: 5 March 2026
Version: 25.12.11
Security checks
- Updated the vulnerability database (VDB) to version 20260303
- Added security check for CWP Remote Code Execution CVE-2025-48703
- Improved detection of MongoDB vulnerabilities
- Updated severity ratings for CaddyWebServer versions 0.10.3, 0.10.4, 0.10.5, 0.10.6, 0.10.7, 0.10.8, 0.10.9, 0.10.10, 0.10.11, 0.10.12, 0.10.13, 0.10.14, 0.11.0, 0.11.1, 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 2.0.0, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.3, 2.3.0, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.7.0, 2.7.1, 2.7.2, 2.7.3, 2.7.4 from High to Critical
- Updated severity rating for Grafana version 10.4.0 from Low to Medium
- Updated severity rating for Markdownit version 14.1.0 from Medium to High
- Updated severity ratings for Moodle versions 4.2.10, 4.2.11 from Medium to High
- Updated severity ratings for Piwigo versions 14.0.0, 14.1.0, 14.2.0, 14.3.0, 14.4.0 from Medium to High
- Added vulnerability detection for Angular:
- Medium: CVE-2026-22610, CVE-2026-27970
- Added vulnerability detection for CKEditor:
- Medium: CVE-2021-21254, CVE-2024-45613, CVE-2025-61261
- Added vulnerability detection for CaddyWebServer:
- Critical: CVE-2026-27586, CVE-2026-27587, CVE-2026-27588, CVE-2026-27590
- Medium: CVE-2026-27585, CVE-2026-27589
- Added vulnerability detection for CakePHP:
- Medium: CVE-2026-23643
- Added vulnerability detection for Chamilo:
- Medium: CVE-2026-1106
- Added vulnerability detection for Craft CMS:
- Medium: CVE-2026-27126, CVE-2026-27127, CVE-2026-27128
- Added vulnerability detection for Dolibarr:
- High: CVE-2019-25450, CVE-2019-25452
- Medium: CVE-2021-47779
- Added vulnerability detection for Grafana:
- Medium: CVE-2025-41117, CVE-2026-21722
- Low: CVE-2026-21725
- Added vulnerability detection for Markdownit:
- High: CVE-2026-2327
- Added vulnerability detection for MongoDb:
- High: CVE-2026-1847, CVE-2026-1848, CVE-2026-1849, CVE-2026-1850
- Medium: CVE-2026-25609, CVE-2026-25610, CVE-2026-25613
- Added vulnerability detection for Moodle:
- High: CVE-2026-26045, CVE-2026-26046
- Medium: CVE-2026-26047
- Added vulnerability detection for NextJsReactFramework:
- High: CVE-2025-59472
- Added vulnerability detection for Piwigo:
- High: CVE-2024-48928
- Medium: CVE-2025-62512
Release 20260224
Release date: 25 February 2026
Version: 25.12.10
Security checks
- Updated the vulnerability database (VDB) to version 20260224
- Updated severity ratings for PostgreSQL versions 14.13, 15.8, 16.4, 17.0 from Medium to High
- Added security check for WordPress plugin detection
- Improved .htaccess detection
- Added security check for Laravel Livewire RCE CVE-2025-54068
- Added security check for SmartMail Authbypass CVE-2026-23760
- Added vulnerability detection for Angular:
- Medium: CVE-2025-66412
- Added vulnerability detection for Craft CMS:
- Added vulnerability detection for Grafana:
- High: CVE-2026-21720
- Added vulnerability detection for Hiawatha:
- Medium: CVE-2025-57783
- Low: CVE-2025-57784
- Added vulnerability detection for Jenkins:
- High: CVE-2026-27099
- Medium: CVE-2026-27100
- Added vulnerability detection for Lodash:
- Medium: CVE-2025-13465
- Added vulnerability detection for NextJsReactFramework:
- High: CVE-2025-59471
- Added vulnerability detection for PostgreSQL:
- High: CVE-2026-2004, CVE-2026-2005, CVE-2026-2006, CVE-2026-2007
- Medium: CVE-2026-2003
- Added vulnerability detection for PrestaShop:
- Medium: CVE-2026-25597
- Added vulnerability detection for React:
- High: CVE-2026-23864
- Added vulnerability detection for Skipper:
- High: CVE-2026-23742, CVE-2026-24470
- Added vulnerability detection for XWikiplatform:
- Medium: CVE-2025-66472, CVE-2026-26000
- Added vulnerability detection for axios:
- High: CVE-2026-25639
- Removed vulnerability detection for bootstrap.js:
Release 20260202
Release date: 3 February 2026
Version: 25.12.9
Security checks
- Updated the vulnerability database (VDB) to version 20260202
- Added comprehensive JWT authentication bypass detection
- High: JWT Signature Bypass via None Algorithm
- High: JWT Signature is not Verified
- High: JWT Signature Bypass via kid SQL injection
- High: JWT Signature Bypass via kid Path Traversal
- High: JWT Signature Bypass via unvalidated jwk parameter
- High: Unvalidated JWT jku parameter
- High: Unvalidated JWT x5u parameter
- High: JWT Signature Bypass via unvalidated jku parameter
- High: JWT Signature Bypass via unvalidated x5u parameter
- High: JWT Signature Bypass via unvalidated x5c parameter
- Added authorization vulnerability detection
- High: Horizontal Broken Function Level Authorization (BFLA)
- High: Unauthenticated Access to Sensitive Functions
- High: Horizontal IDOR/BOLA (Broken Object Level Authorization)
- High: Vertical Broken Function Level Authorization (BFLA)
- High: Vertical IDOR/BOLA (Broken Object Level Authorization)
- Added sensitive information exposure detection
- High: API Sensitive Info(PII) accessible without authentication
- Medium: Resource Accessible Without Required Authentication
- Added API inventory management checks
- Medium: API Authentication Bypass Using a Test/Staging Host Header
- Added microservice security checks
- High: Microservice Directory Traversal
- Added vulnerability detection for Java:
- Medium: CVE-2026-21925, CVE-2026-21933
- High: CVE-2026-21932, CVE-2026-21945
- Added vulnerability detection for Jetty:
- High: CVE-2025-5115
- Added vulnerability detection for Joomla:
- Medium: CVE-2025-63082, CVE-2025-63083
- Removed vulnerability detection for LiferayPortal:
- Added vulnerability detection for LimeSurvey:
- Medium: CVE-2020-36993, CVE-2025-41376
- High: CVE-2024-39063
- Critical: CVE-2025-41375
- Added vulnerability detection for MySQL:
- Medium: CVE-2026-21964
- Added vulnerability detection for Oracle:
- High: CVE-2026-21939
- Added vulnerability detection for Oracle HTTP Server:
- Critical: CVE-2026-21962
- Added vulnerability detection for osTicket:
- High: CVE-2026-22200
- Added vulnerability detection for phpMyFAQ:
- Medium: CVE-2026-24420, CVE-2026-24421
- High: CVE-2026-24422
- Updated severity for Oracle 23.8 from Medium to High
- Updated severity for osTicket 1.17, 1.17.1, 1.17.3, 1.17.4, 1.17.5, 1.17.6, 1.18 from Medium to High
- Added Zimbra Collaboration Suite (ZCS) Local File Inclusion check CVE-2025-68645
Release 20260129
Release date: 29 January 2026
Version: 25.12.8
Security checks
- Updated the vulnerability database (VDB) to version 20260127
- Improved XSS detection
- Added vulnerability detection for e107:
- High: CVE-2022-50939
- Medium: CVE-2022-50905
Resolved issue
- Fixed notifications
Release 20260121
Release date: 21 January 2026
Version: 25.12.7
Security checks
- Updated the vulnerability database (VDB) to version 20260127
- Updated severity rating for Craft CMS version 3.9.15 from Medium to Critical
- Updated severity ratings for Craft CMS versions 4.4.16, 4.4.16.1, 4.4.17, 4.5.0, 4.14.9, 4.14.10, 4.14.11, 4.14.11.1, 4.14.12, 4.14.13, 4.14.14, 4.14.15, 4.15.0, 4.15.0.1, 4.15.0.2, 4.15.1, 4.15.2, 4.15.3, 4.15.4, 4.15.5, 4.15.6, 4.15.6.1, 5.6.10, 5.6.10.1, 5.6.10.2, 5.6.11, 5.6.12, 5.6.13, 5.6.14, 5.6.15, 5.6.17, 5.7.0, 5.7.1, 5.7.2, 5.7.3, 5.7.4, 5.7.5, 5.7.6, 5.7.7, 5.7.8, 5.7.8.1, 5.7.8.2 from High to Critical
- Updated severity rating for Grafana version 12.0.0 from High to Critical
- Updated severity ratings for e107 versions 2.1.4, 2.3.2 from Medium to High
- Added vulnerability detection for Craft CMS:
- Critical: CVE-2025-68456
- High: CVE-2025-68454, CVE-2025-68455
- Medium: CVE-2025-68436, CVE-2025-68437
- Added vulnerability detection for Grafana:
- Critical: CVE-2025-41115
- Added vulnerability detection for Python:
- Medium: CVE-2025-13837
- Added vulnerability detection for SharePoint:
- High: CVE-2026-20943, CVE-2026-20947, CVE-2026-20948, CVE-2026-20951, CVE-2026-20963
- Medium: CVE-2026-20958, CVE-2026-20959
- Added vulnerability detection for e107:
- High: CVE-2022-50907, CVE-2022-50916, CVE-2025-11941
- Medium: CVE-2022-50906, CVE-2025-61505
- Added vulnerability detection for typo3CMS:
- High: CVE-2025-59022, CVE-2026-0859
- Medium: CVE-2025-59020, CVE-2025-59021
Release 20260113
Release date: 13 January 2026
Version: 25.12.6
Security checks
- Added coverage for the security vulnerability CVE-2025-66516
- Improved the accuracy of Invicti security checks by reducing false positives for XXE vulnerabilities on specific REST endpoints
- Updated the vulnerability database (VDB) to version 20260113
- Added vulnerability detection for OpenCart:
- Medium: CVE-2025-15116
- Added vulnerability detection for PHP:
- Added vulnerability detection for WordPress:
- High: CVE-2024-31210
- Added vulnerability detection for phpMyFAQ:
- High: CVE-2025-62519, CVE-2025-69200
- Medium: CVE-2025-68951
Release 20260107
Release date: 7 January 2026
Version: 25.12.5
Security checks
- Updated the Vulnerability Database (VDB) to version 20260106
- Added 15 new versions for 18 technologies and 7 new CVEs
- Updated severity ratings for MongoDB versions 4.2.18, 4.3.0-4.3.3, 4.4.29, 5.0.30-5.0.31, 6.0.23-6.0.26, 8.0.13-8.0.15, 8.2.0-8.2.1 from Medium to High
- Updated severity rating for Podcast Generator version 3.2.9 from Medium to Critical
- Updated severity ratings for Python versions 3.10.10-3.10.19, 3.11-3.11.14, 3.12-3.12.5 from High to Critical
- Updated severity rating for Python version 3.12.6 from Medium to Critical
- Added vulnerability detection for CrushFTP:
- Medium: CVE-2025-63419
- Added vulnerability detection for MongoDB:
- High: CVE-2025-14847
- Added vulnerability detection for Podcast Generator:
- Critical: CVE-2023-53899
- Added vulnerability detection for Python:
- Critical: CVE-2025-13836
- Added vulnerability detection for Roundcube:
- High: CVE-2025-68460
- Medium: CVE-2025-68461
- Added vulnerability detection for phpMyFAQ:
- High: CVE-2023-53929
2025
Security checks, vulnerability database updates, and Runtime SCA enhancements released in 2025.
Release 20251230
Release date: 30 December 2025
Version: 25.12.4
Security checks
- Updated the Vulnerability Database (VDB) to version 20251230
- Added 84 new versions for 50 technologies and 133 new CVEs
- Updated severity rating for Dotclear version 2.29 from Medium to High
- Updated severity ratings for Jenkins versions 2.426.3, 2.452.4, 2.462.1-2.462.3, 2.471-2.492, 2.492.1-2.492.3, 2.493-2.501, 2.504 from Medium to High
- Updated severity ratings for Liferay DXP versions 2024.q1.14-2024.q1.18 from High to Critical
- Updated severity ratings for Liferay DXP versions 2024.q3.0, 2024.q4.7, 2025.q1.0-2025.q1.14, 2025.q2.0 from Medium to Critical
- Updated severity rating for Liferay Portal version 7.4.3.132 from Medium to Critical
- Updated severity ratings for Next.js React Framework versions 15.2.6-15.2.7, 15.3.6-15.3.7, 15.4.8-15.4.9 from Critical to High
- Updated severity rating for Next.js React Framework version 15.6.0 from High to Critical
- Updated severity ratings for React versions 19.0.1-19.0.2, 19.1.2-19.1.3 from Critical to High
- Updated severity ratings for Roundcube versions 1.5.6, 1.6.5-1.6.6 from Medium to High
- Updated severity rating for Ruby version 1.9.0 from Critical to High
- Added vulnerability detection for Coppermine:
- High: CVE-2023-53868
- Added vulnerability detection for Dotclear:
- High: CVE-2023-53952, CVE-2024-58281
- Added vulnerability detection for Jenkins:
- High: CVE-2025-67635
- Medium: CVE-2025-67636, CVE-2025-67637, CVE-2025-67638
- Low: CVE-2025-67639
- Added vulnerability detection for Liferay DXP:
- Critical: CVE-2025-43773
- High: CVE-2025-43790, CVE-2025-43793, CVE-2025-43796, CVE-2025-43816, CVE-2025-4581
- Medium: CVE-2025-43771, CVE-2025-43775, CVE-2025-43776, CVE-2025-43779, CVE-2025-43781, CVE-2025-43782, CVE-2025-43783, CVE-2025-43784, CVE-2025-43785, CVE-2025-43786, CVE-2025-43787, CVE-2025-43788, CVE-2025-43789, CVE-2025-43791, CVE-2025-43792, CVE-2025-43794, CVE-2025-43795, CVE-2025-43797, CVE-2025-43798, CVE-2025-43799, CVE-2025-43800, CVE-2025-43803, CVE-2025-43805, CVE-2025-43807, CVE-2025-43808, CVE-2025-43809, CVE-2025-43819, CVE-2025-43821, CVE-2025-43822, CVE-2025-43823, CVE-2025-43824, CVE-2025-43825, CVE-2025-43826, CVE-2025-43827, CVE-2025-43829, CVE-2025-4388, CVE-2025-4576, CVE-2025-4599, CVE-2025-4604, CVE-2025-4655, CVE-2025-62243, CVE-2025-62244
- Added vulnerability detection for Liferay Portal:
- Critical: CVE-2025-43773
- High: CVE-2025-43790, CVE-2025-43793, CVE-2025-43796, CVE-2025-43816, CVE-2025-4581
- Medium: CVE-2025-43771, CVE-2025-43775, CVE-2025-43776, CVE-2025-43779, CVE-2025-43781, CVE-2025-43782, CVE-2025-43783, CVE-2025-43784, CVE-2025-43785, CVE-2025-43786, CVE-2025-43787, CVE-2025-43788, CVE-2025-43789, CVE-2025-43791, CVE-2025-43792, CVE-2025-43794, CVE-2025-43795, CVE-2025-43797, CVE-2025-43799, CVE-2025-43800, CVE-2025-43803, CVE-2025-43805, CVE-2025-43807, CVE-2025-43808, CVE-2025-43809, CVE-2025-43819, CVE-2025-43821, CVE-2025-43822, CVE-2025-43823, CVE-2025-43824, CVE-2025-43825, CVE-2025-43826, CVE-2025-43827, CVE-2025-43829, CVE-2025-4388, CVE-2025-4576, CVE-2025-4599, CVE-2025-4604, CVE-2025-4655, CVE-2025-62243, CVE-2025-62244
- Added vulnerability detection for Markdown-it:
- Medium: CVE-2025-7969
- Added vulnerability detection for Masa CMS:
- Medium: CVE-2025-66492
- Added vulnerability detection for MyBB:
- High: CVE-2023-53979
- Medium: CVE-2023-53976, CVE-2023-53977, CVE-2023-53978
- Added vulnerability detection for Podcast Generator:
- Medium: CVE-2023-53918, CVE-2023-53919, CVE-2023-53920
- Added vulnerability detection for ProjectSend:
- Critical: CVE-2023-53980
- High: CVE-2023-53905, CVE-2023-53930
- Medium: CVE-2023-53906
- Added vulnerability detection for Python:
- Medium: CVE-2025-12084
- Added vulnerability detection for ReviveAdserver:
- Medium: CVE-2023-53931
- Added vulnerability detection for Roundcube:
- High: CVE-2025-49113
- Medium: CVE-2024-57004
- Added vulnerability detection for Rukovoditel:
- High: CVE-2023-53913
- Medium: CVE-2023-53897, CVE-2023-53898
- Added vulnerability detection for Serendipity:
- High: CVE-2023-53933, CVE-2024-58282
- Medium: CVE-2023-53932
- Added vulnerability detection for Tornado Web Server:
- High: CVE-2025-47287, CVE-2025-67725, CVE-2025-67726
- Medium: CVE-2025-67724
- Added vulnerability detection for XWiki platform:
- High: CVE-2025-66473
- Added vulnerability detection for ZenPhoto:
- Medium: CVE-2023-53915, CVE-2023-53916
Improvements
- Updated vulnerability classifications to align with OWASP Top 10 2025 categories
- Updated OWASP Top 10 scan profile to align with OWASP Top 10 2025 categories
Release 20251217
Release date: 17 December 2025
Version: 25.12.3
Security checks
- Updated the Vulnerability Database (VDB) to version 20251215
- Added 179 new versions for 37 technologies and 118 new CVEs
- Updated severity rating for Apache 2.4.64 from Medium to High
- Updated severity ratings for Liferay DXP versions 2023.q3.0, 2023.q4.6-10, 2024.q1.1-5, 7.0-7.2 from Medium/High to High/Critical
- Updated severity ratings for Liferay Portal versions 6.2, 7.0.0, 7.0.6, 7.2.0-7.2.1, 7.3.0-7.3.2, 7.4.3.10-7.4.3.119 from Medium/High to Critical
- Updated severity ratings for MongoDB versions 7.0.20-7.0.25, 8.0.9-8.0.12, 8.1.0 from Medium to High
- Updated severity ratings for Next.js React Framework versions 14.2.25-14.2.29 from Medium to High
- Added vulnerability detection for Angular:
- Medium: CVE-2025-61261
- Added vulnerability detection for Apache:
- High: CVE-2025-55753, CVE-2025-58098, CVE-2025-59775
- Medium: CVE-2025-65082, CVE-2025-66200
- Added vulnerability detection for Django:
- High: CVE-2025-64460
- Medium: CVE-2025-13372
- Added vulnerability detection for Liferay DXP:
- Critical: CVE-2025-3594, CVE-2025-43766
- High: CVE-2025-3586, CVE-2025-43768, CVE-2025-43801, CVE-2025-43813
- Medium: CVE-2025-43746, CVE-2025-43747, CVE-2025-43754, CVE-2025-43755, CVE-2025-43756, CVE-2025-43757, CVE-2025-43758, CVE-2025-43759, CVE-2025-43760, CVE-2025-43762, CVE-2025-43763, CVE-2025-43765, CVE-2025-43767, CVE-2025-43770, CVE-2025-43774, CVE-2025-43778, CVE-2025-43780, CVE-2025-43804, CVE-2025-43806, CVE-2025-43810, CVE-2025-43811, CVE-2025-43814, CVE-2025-43815, CVE-2025-43817, CVE-2025-43818, CVE-2025-43820, CVE-2025-43828, CVE-2025-3587, CVE-2025-3588, CVE-2025-3589, CVE-2025-3590, CVE-2025-3591, CVE-2025-3592, CVE-2025-3593, CVE-2025-3595, CVE-2025-3596, CVE-2025-3597, CVE-2025-4363, CVE-2025-4368, CVE-2025-4373, CVE-2025-4378, CVE-2025-4383
- Added vulnerability detection for Liferay Portal:
- Critical: CVE-2025-3594, CVE-2025-43766
- High: CVE-2025-3586, CVE-2025-43768, CVE-2025-43801, CVE-2025-43813
- Medium: CVE-2025-43746, CVE-2025-43754, CVE-2025-43755, CVE-2025-43756, CVE-2025-43757, CVE-2025-43761, CVE-2025-43762, CVE-2025-43763, CVE-2025-43765, CVE-2025-43767, CVE-2025-43770, CVE-2025-43774, CVE-2025-43778, CVE-2025-43780, CVE-2025-43804, CVE-2025-43806, CVE-2025-43810, CVE-2025-43811, CVE-2025-43814, CVE-2025-43815, CVE-2025-43817, CVE-2025-43818, CVE-2025-43820, CVE-2025-43828, CVE-2025-3587, CVE-2025-3588, CVE-2025-3589, CVE-2025-3590, CVE-2025-3591, CVE-2025-3592, CVE-2025-3593, CVE-2025-3595, CVE-2025-3596, CVE-2025-3597, CVE-2025-4363, CVE-2025-4368, CVE-2025-4373, CVE-2025-4378, CVE-2025-4383
- Added vulnerability detection for MongoDB:
- High: CVE-2025-13644
- Medium: CVE-2025-12657, CVE-2025-13643, CVE-2025-14345
- Added vulnerability detection for Next.js React Framework:
- High: CVE-2025-55184, CVE-2025-67779
- Medium: CVE-2025-55183
- Added vulnerability detection for React:
- High: CVE-2025-55184, CVE-2025-67779
- Medium: CVE-2025-55183
- Added vulnerability detection for SharePoint:
- Critical: CVE-2025-64672
- High: CVE-2025-62555, CVE-2025-62558, CVE-2025-62559, CVE-2025-62562
Improvements
- Improved detection of DOM XSS vulnerabilities
- Updated the alert text of the most detected vulnerabilities
Resolved issues
- Improved detection of "Sensitive pages could be cached" vulnerabilities
- Improved detection of "Open Redirect" vulnerabilities
Release 20251209
Release date: 9 December 2025
Version: 25.12.2
Security checks
- Updated the Vulnerability Database (VDB) to version 20251209
Release 20251205
Release date: 5 December 2025
Version: 25.12.1
Security checks
- Implemented security checks for Next.js/React Server Components RCE:
Release 20251203
Release date: 3 December 2025
Version: 25.11.3
Security checks
- Updated the Vulnerability Database (VDB) to version 20251202
- Updated severity ratings for ReviveAdserver versions 5.3.0, 5.3.1, 5.4.0, 5.4.1, 5.5.0, 5.5.1, 5.5.2 from Medium to High
- Added vulnerability detection for Drupal:
- CVE-2025-13080 (Medium)
- CVE-2025-13081 (Medium)
- CVE-2025-13082 (Medium)
- CVE-2025-13083 (Low)
- Added vulnerability detection for Piwigo:
- CVE-2025-62406 (High)
- Added vulnerability detection for ReviveAdserver:
- CVE-2025-48986 (High)
- CVE-2025-48987 (Medium)
- CVE-2025-55124 (Medium)
- Added vulnerability detection for MoveItTransfer:
- CVE-2025-13147 (Medium)
Improvements
- Improved password detection when leaked in responses
- Improved detection of DOM XSS vulnerabilities
Resolved issues
- Improved detection of chatbots
Release 20251125
Release date: 25 November 2025
Version: 25.11.2
Security checks
- Added detection for the Fortinet FortiWeb authentication bypass vulnerability (CVE-2025-64446)
- Added detection for the Citrix NetScaler memory leak and reflected XSS vulnerability (CVE-2025-12101)
- Improved detection of SQL injection attempts in prepared statements used with NodeJS and MySQL
- Added detection for the Oracle Identity Manager authentication bypass leading to RCE (CVE-2025-61757)
- Updated the Vulnerability Database (VDB) to version 20251125
Resolved issue
- Fixed an issue in the script that identifies API resources missing required authentication
Release 20251120
Release date: 20 November 2025
Version: 25.11.1
Security checks
- Added check for Django SQL Injection via
_connector parameter- CVE-2025-64459 - Updated the Vulnerability Database (VDB) to version 20251118
Improvement
- Updated High Risk profile to include Blind XSS vulnerability checks
Release 20251105
Release date: 5 November 2025
Security checks
- Improved Local Path Traversal detection in J2EE environments to cover CVE-2025-55752
- Added detection for Magento authentication bypass (SessionReaper) - CVE-2025-54236
- Updated the Vulnerability Database (VDB) to version 20251104
Improvements
- Improved detection of sensitive information and personally identifiable information (PII)
Resolved issues
- Resolved an issue where XSS findings in JSON responses didn't display attack details
- Fixed the issue where sensitive data was not highlighted in the response for Sensitive Data Exposure vulnerabilities
- Resolved classification of standard XSS vulnerabilities that depend on how legacy browsers handle encoding
Release 20251031
Release date: 31 October 2025
Security checks
- Updated AEM (Adobe Experience Manager) checks to include seven newly reported vulnerabilities from the Hopgoblin toolkit (CVE-2025-54251, CVE-2025-54249, CVE-2025-54252, CVE-2025-54250, CVE-2025-54247, CVE-2025-54248, CVE-2025-54246)
- Updated the Vulnerability Database (VDB) to version 20251006
- Updated the Vulnerability Database (VDB) to version 20251021
- Added detection for the Oracle E-Business Suite remote code execution vulnerability (CVE-2025-61882)
- Added a new information discovery capability to detect sensitive or personally identifiable (PII) data during scans
Improvements
- Increased the severity level of TLS 1.1 usage from “Info” to “Low”
- Added new informational XSS finding types for cases where exploitation depends on the encoding behavior of legacy browsers
Resolved issues
- Removed duplicate CVE findings