It's 2026 and both Wordpress and Ghost keep having SQL injection issues in stock installs.
Conversation
Notices
-
Embed this notice
Thomas 🔭🕹️ (thomasfuchs@hachyderm.io)'s status on Saturday, 25-Jul-2026 01:32:10 JST
Thomas 🔭🕹️
-
Embed this notice
Robbie Coleman :verified: (erraggy@hachyderm.io)'s status on Saturday, 25-Jul-2026 01:37:21 JST
Robbie Coleman :verified:
@thomasfuchs I think we will have SQL injection attacks for as long as we have SQL. Same for paths and ../
-
Embed this notice
Thomas 🔭🕹️ (thomasfuchs@hachyderm.io)'s status on Saturday, 25-Jul-2026 01:52:00 JST
Thomas 🔭🕹️
@cthos no I meant the one in may, but I'd really recommend to keep current (there was a minor release today)
-
Embed this notice
cthos 🐱 (cthos@mastodon.cthos.dev)'s status on Saturday, 25-Jul-2026 01:52:01 JST
cthos 🐱
@thomasfuchs Re: Ghost, is there a new one or do you mean the one back in May? (I'm not seeing a new one and am worried I've missed something I need to patch right now).
-
Embed this notice
hankg (hankg@friendica.myportal.social)'s status on Saturday, 25-Jul-2026 01:52:23 JST
hankg
@thomasfuchs Seriously?! How? Are they not using standard libraries that combat this problem?
-
Embed this notice