1.
Aretiq on CVE-2026-15748: Forminator Forms (600k+ installs) lets unauthenticated attackers bypass its file-extension blocklist and upload PHP files for remote code execution; fixed in 1.56.2.
Why it matters: This research provides technical context that security teams can use for monitoring and validation.
Skip to content