Five CMS vulnerabilities in two weeks all share the same root cause — AJAX endpoints. Plus WordPress plugin patches and a Joomla scheduler fix.