Latest updates for Xss

Fresh curated links around XSS are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • Clear the Lineup: XSS via innerHTML in cyberbro — Found and Fixed by GSC
  • GHSA-m5f6-4589-m89f (blazer): Stored XSS vulnerability
  • GHSA-4qhx-6wrv-5hg2 (alchemy_cms): Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

dev.to /4 weeks ago

Clear the Lineup: XSS via innerHTML in cyberbro — Found and Fixed by GSC

What I Fixed A Cross-Site Scripting (XSS) vulnerability in cyberbro (122 в­ђ), an open-source OSINT platform. The search highlight feature used .innerHTML with unsanitized user i...

Read source
rubysec.com /1 month ago

GHSA-m5f6-4589-m89f (blazer): Stored XSS vulnerability

Originally appeared on RubySec.An authenticated user can create a malicious query that executes arbitrary JavaScript when another user tries to edit the query. This can be used to...

Read source
rubysec.com /5 days ago

GHSA-4qhx-6wrv-5hg2 (alchemy_cms): Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name...

Originally appeared on RubySec.An improper input sanitization vulnerability in the menu node name rendering allows Author-level users to inject stored JavaScript that executes in a...

Read source
rubysec.com /1 month ago

GHSA-cj75-f6xr-r4g7 (rails-html-sanitizer): Possible XSS vulnerability with certain configurations of rails-html-sanitiz...

Originally appeared on RubySec.## Summary There is a possible cross-site scripting vulnerability in rails-html-sanitizer when the sanitizer is configured to allow an SVG reference...

Read source
rubysec.com /1 month ago

GHSA-r827-6rm4-59pg (alchemy_cms): Stored XSS via unsanitized SVG attachment replacement

Originally appeared on RubySec.## Summary AlchemyCMS registers its SVG sanitizer (SanitizeSvgJob, a Loofah-based scrubber) only as an after_create_commit callback on Alchemy::Atta...

Read source
rubysec.com /5 days ago

GHSA-g7vv-4mjj-6fgm (alchemy_cms): Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name...

Originally appeared on RubySec.An improper input sanitization vulnerability in the Page Properties menu node rendering allows Author-level users to inject stored JavaScript that ex...

Read source
rubysec.com /1 month ago

GHSA-9wjq-cp2p-hrgf (loofah): SVG `href` attribute bypasses local-reference restriction in Loofah

Originally appeared on RubySec.## Summary Loofah's HTML5 sanitizer restricted only the xlink:href attribute on certain SVG elements to local, same-document references. Browsers al...

Read source
cybersecuritynews.com /2 weeks ago

CRLF-Powered Desync Lets Attackers Poison CDN Cache and Serve XSS to Live Users

A limited CRLF injection flaw can be escalated into a severe HTTP desynchronization attack, poisoning CDN caches and delivering XSS payloads to users on legitimate websites. The at...

Read source
gbhackers.com /1 month ago

WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution

WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the login scre...

Read source
habr.com /4 weeks ago

SOP & CORS

Держите открытыми две вкладки. В одной — интернет-банк, куда вы залогинены и где на экране висит ваш баланс. В другой — какой-то сайт, на который вы забрели по ссылке из выдачи, ни...

Read source
previousnext.com.au /2 days ago

PreviousNext: If you're using Twig's raw filter with Drupal, you're doing it wrong

With some recent security advisories for Cross Site Scripting (XSS), it feels like an opportune time to remind those who author Twig templates for Drupal:If you're using Twig's |ra...

Read source
smashingmagazine.com /1 month ago

Weaponizing And Defending The React Flight Protocol: Deserialization Sinks In RSCs

While React Server Components rely on the custom Flight protocol to stream interactive UIs, this same mechanism introduces powerful deserialization sinks that attackers can exploit...

Read source
thehackernews.com /1 month ago

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstra...

Read source
rubysec.com /1 month ago

GHSA-8whx-365g-h9vv (loofah): Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace charact...

Originally appeared on RubySec.## Summary Loofah::HTML5::Scrub.allowed_uri? does not correctly reject javascript: URIs when the scheme is split or prefixed by the HTML5 named char...

Read source
rubysec.com /1 month ago

GHSA-5qhf-9phg-95m2 (loofah): Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character refere...

Originally appeared on RubySec.## Summary Loofah::HTML5::Scrub.allowed_uri? does not correctly reject javascript: or vbscript: URIs when the scheme is split by a numeric character...

Read source
dzone.com /1 week ago

Making User-Generated Sites Embeddable: X-Frame-Options vs CSP Frame-Ancestors

If you let users publish something, such as a page, prototype, or dashboard, sooner or later you want an "embed this" button so they can drop it into a blog, a portfolio, or docs,...

Read source
rubysec.com /1 month ago

CVE-2026-45572 (decidim-core): Decidim - HTML content blocks allow stored script execution

Originally appeared on RubySec.## Description A privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an `HTML block`, and the public...

Read source
cybersecuritynews.com /1 month ago

WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full remote code execution on the...

Read source
cybersecuritynews.com /1 month ago

XCSSET v40 Abuses Chrome DevTools Protocol to Steal Cookies and Run Commands

XCSSET has returned with a way to target macOS developers. The latest version, v40, hides inside poisoned Xcode projects and can turn a local build into a supply-chain compromise....

Read source
thehackernews.com /2 weeks ago

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongo...

Read source
itmedia.co.jp /1 month ago

「Xであなたをブロックした人が分かる」サイト拡散 ソースコードを見たら、IDとパスワード外部送信

「ブロックの状況を確認できる」とうたうWebサイトへの注意喚起がX上で広がっている。ITmedia NEWS編集部がソースコードを確認したところ、入力したIDとパスワードをそのまま外部のサーバへ送る...

Read source
thehackernews.com /1 month ago

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same...

Read source
rubysec.com /3 weeks ago

CVE-2026-73330 (camaleon_cms): CamaleonCMS 2.9.1 Server-Side Template Injection via test_email Action

Originally appeared on RubySec.CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by e...

Read source
drupal.org /1 month ago

Security advisories: Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011

Project: Drupal coreDate: 2026-July-15Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross-site scriptingAf...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Xss

feeds.dzone.com

Recent coverage from public sources
Public source

rubyland.news

Recent coverage from public sources
Public source

cybersecuritynews.com

Recent coverage from public sources
Public source

dev.to

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source

gbhackers.com

Recent coverage from public sources
Public source