Tag: xss
-
WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal
WordPress has released version 7.1.1, a maintenance and security update that addresses 11 vulnerabilities affecting core platform components, themes, REST API functionality, comments, XML-RPC, and plugin management. Site administrators are strongly urged to update immediately due to the potential impacts of stored cross-site scripting, authenticated path traversal, authorization bypasses, and information disclosure flaws. This release…
-
Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft
Tags: advisory, credentials, cyber, flaw, rce, remote-code-execution, theft, update, vulnerability, xssJenkins has released security updates addressing 20 vulnerabilities across 13 plugins, including multiple high-severity flaws that could allow authorized attackers to bypass Groovy sandbox protections and execute arbitrary code on Jenkins controllers. The advisory, dated September 16, 2026, also addresses stored cross-site scripting (XSS), server-side request forgery (SSRF), credential exposure, path traversal, OAuth token hijacking,…
-
Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft
Tags: advisory, credentials, cyber, flaw, rce, remote-code-execution, theft, update, vulnerability, xssJenkins has released security updates addressing 20 vulnerabilities across 13 plugins, including multiple high-severity flaws that could allow authorized attackers to bypass Groovy sandbox protections and execute arbitrary code on Jenkins controllers. The advisory, dated September 16, 2026, also addresses stored cross-site scripting (XSS), server-side request forgery (SSRF), credential exposure, path traversal, OAuth token hijacking,…
-
Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories
A stored cross-site scripting (XSS) vulnerability in Telegram Desktop could enable attackers to steal the contents of exported chat histories by embedding malicious code in an inline keyboard button, according to security researchers. This issue affects the HTML chat export feature in Telegram Desktop builds released before Beta version 6.9.4 and Stable version 7.0.1. Researchers…
-
Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection
Okta has released security updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. These vulnerabilities could allow authenticated attackers to trigger stored cross-site scripting (XSS), bypass Protected Rule authorization controls, or execute unintended SQL commands against configured backend databases under specific deployment conditions. All three vulnerabilities were disclosed on September…
-
Roundcube Fixes 12 Security Flaws Including Zero-Click XSS and SSRF Bypass
Roundcube has released security updates 1.6.19 and 1.7.4, which address 12 vulnerabilities affecting its 1.6 LTS and 1.7 Webmail branches. The flaws include a zero-click stored cross-site scripting (XSS) vulnerability, several bypasses of remote content filtering, email header injection bugs, cross-user contact access issues, and a server-side request forgery (SSRF) bypass. Published on September 6,…
-
Who Is REvil’s Ransomware Developer Anatoly Sergeevitsch Kravchuk?
Dear blog readers. This is Dancho. A reader recently approached me with a detailed research and analysis for Quake3 a XSS forum moderator where he connected the dots that Quake3 is also the main developer of the REvil ransomware where he asked me to go ahead and publish it. So who’s Anatoly Sergeevitsch Kravchuk? Dark…
-
Escape found the same XSS in two AI chatboxes. The vulnerability was in the Markdown renderer.
Weeks apart, at two unrelated companies, Escape’s AI pentesting agent found the same stored XSS. Both had shipped a customer-facing chat where the model emits Markdown and the frontend renders it with raw HTML enabled and no sanitizer, so anything the model can be made to say executes First seen on securityboulevard.com Jump to article:…
-
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server.Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai, First seen…
-
Django Flaws Let Attackers Trigger RCE, SSRF, DoS, and XSS Attacks
The Django project has released security updates, specifically Django 6.0.8 and Django 5.2.17, to address four vulnerabilities that could lead to server-side request forgery (SSRF), arbitrary file writes with potential for remote code execution (RCE), denial-of-service (DoS), and stored cross-site scripting (XSS) attacks. An advisory posted by Natalia Bidart on August 4, 2026, urges all…
-
Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection
Tags: access, ai, api, attack, ceo, credentials, detection, email, endpoint, exploit, intelligence, marketplace, threat, waf, xssThe WAF gap no one is talking about Your WAF is doing its job. It’s blocking SQLi, XSS, and the usual suspects. But here’s the problem: it wasn’t built for APIs, and it definitely wasn’t built for AI agents. APIs now power nearly every digital experience. And AI agents, the automated systems that access your…
-
Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws
Zimbra has released version 10.1.20 of its Collaboration Suite (ZCS) to address multiple high-severity security vulnerabilities. This release includes a critical command injection flaw in the SNMP monitoring component and several cross-site scripting (XSS) issues affecting the Classic Web Client. The update, published on July 20, 2026, provides a permanent fix for a previously disclosed…
-
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component.As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.Also patched…
-
Prompt injection is becoming the XSS of the web agent era
Autonomous web agents read whatever a page displays, and much of that content comes from strangers. Product reviews, seller listings, and advertisements sit beside trusted … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/xss-web-agent-prompt-injection/
-
Zimbra urges patching of critical XSS vulnerability in Classic Web Client
First seen on scworld.com Jump to article: www.scworld.com/brief/zimbra-urges-patching-of-critical-xss-vulnerability-in-classic-web-client
-
Chinese Cyberespionage Exploits University Roundcube Servers
Campaign Combines XSS and Deserialization to Steal Credentials and Deploy Malware. Proofpoint identified a likely China-aligned espionage group exploiting chained Roundcube vulnerabilities to steal credentials and deploy persistent malware against U.S. and Canadian university departments conducting sensitive physics, engineering and national security research. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-cyberespionage-exploits-university-roundcube-servers-a-32165
-
IBM WebSphere Application Server Hit by Critical XSS and Path Traversal Vulnerabilities
IBM has disclosed several security vulnerabilities in its WebSphere Application Server that put enterprise environments at risk of cross-site scripting (XSS) and path-traversal attacks. These vulnerabilities could allow attackers to compromise administrative sessions and access sensitive data. The issues, identified as CVE-2026-11712, CVE-2026-11595, and CVE-2026-11708, affect widely deployed versions 8.5 and 9.0 of the application…
-
Webmin Stored XSS Vulnerability Lets Attackers Exploit Root Users
A newly disclosed stored cross-site scripting (XSS) vulnerability in Webmin has raised significant security concerns, as it allows attackers with limited privileges to target and potentially compromise root users. This vulnerability, tracked as CVE-2026-22678, affects Webmin versions before 2.641 and resides in the System and Server Status module, a commonly used component for monitoring system…
-
(g+) Exchange OWA XSS: Angriff per Mail und ein Patch, der nicht alle erreicht
Ein aktiv ausgenutzter Zero-Day in Exchange OWA ist gepatcht, für 2016 und 2019 aber nur gegen Aufpreis. Was zu tun ist. First seen on golem.de Jump to article: www.golem.de/news/exchange-owa-xss-angriff-per-mail-und-ein-patch-der-nicht-alle-erreicht-2606-209967.html
-
Multiple VMware Stored XSS Flaw Enable Attackers to Inject Malicious Scripts
VMware has disclosed multiple high-severity stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation (VCF) Operations, potentially allowing attackers to inject malicious scripts and compromise administrative environments. The issues, tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, were published under advisory VMSA-2026-0004 on June 8, 2026, and carry a combined CVSS v3 base score of 8.0, indicating…
-
Multiple VMware Stored XSS Flaw Enable Attackers to Inject Malicious Scripts
VMware has disclosed multiple high-severity stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation (VCF) Operations, potentially allowing attackers to inject malicious scripts and compromise administrative environments. The issues, tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, were published under advisory VMSA-2026-0004 on June 8, 2026, and carry a combined CVSS v3 base score of 8.0, indicating…
-
Multiple VMware Stored XSS Flaw Enable Attackers to Inject Malicious Scripts
VMware has disclosed multiple high-severity stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation (VCF) Operations, potentially allowing attackers to inject malicious scripts and compromise administrative environments. The issues, tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, were published under advisory VMSA-2026-0004 on June 8, 2026, and carry a combined CVSS v3 base score of 8.0, indicating…
-
Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts
pretalx XSS flaw lets attackers hijack conference organizer accounts, steal sessions, auto-accept talks, and demote admins. Patched in v2026.1.0. First seen on hackread.com Jump to article: hackread.com/zero-click-pretalx-xss-hackers-hijack-conference-accounts/
-
Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts
pretalx XSS flaw lets attackers hijack conference organizer accounts, steal sessions, auto-accept talks, and demote admins. Patched in v2026.1.0. First seen on hackread.com Jump to article: hackread.com/zero-click-pretalx-xss-hackers-hijack-conference-accounts/
-
Microsoft kämpft mit zwei Schwachstellen – XSS in Exchange, BitLocker durch Downgrade-Angriffe angreifbar
First seen on security-insider.de Jump to article: www.security-insider.de/exchange-xss-cve-2026-42897-bitlocker-luecke-a-2d490f90f669e6d42f72dbdb83392052/
-
Jenkins Plugin Updates Fix Path Traversal and Stored XSS Bugs
The Jenkins project released a critical security advisory addressing seven vulnerabilities across multiple widely used plugins. The disclosed flaws include high-severity path traversal and stored cross-site scripting (XSS) vulnerabilities that could allow threat actors to execute arbitrary code or hijack user sessions. All vulnerabilities were responsibly disclosed through the Jenkins Bug Bounty Program, which the…
-
Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks
Over 10,000 Zimbra Collaboration Suite (ZCS) instances exposed online are vulnerable to ongoing attacks exploiting a cross-site scripting (XSS) security flaw. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-says-zimbra-flaw-now-exploited-over-10k-servers-vulnerable/
-
Critical Spring Authorization Server Issue Exposes Systems to XSS and SSRF Attacks
A critical vulnerability, tracked as CVE-2026-22752, has been disclosed in Spring Security Authorization Server, affecting organizations running Dynamic Client Registration endpoints. The flaw allows attackers to inject malicious client metadata, potentially leading to Stored Cross-Site Scripting (XSS), Privilege Escalation, and Server-Side Request Forgery (SSRF) attacks. The vulnerability was responsibly reported by security researcher Kelvin Mbogo and officially disclosed…
-
BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks
Germany’s Federal Criminal Police Office (aka BKA or the Bundeskriminalamt) has unmasked the real identity of the main threat actors associated with the now-defunct REvil (aka Sodinokibi) ransomware-as-a-service (RaaS) operation.The threat actor, who went by the alias UNKN, functioned as a representative of the group, advertising the ransomware in June 2019 on the XSS cybercrime…

