GHSA-m5f6-4589-m89f (blazer): Stored XSS vulnerability
Originally appeared on RubySec.An authenticated user can create a malicious query that executes arbitrary JavaScript when another user tries to edit the query. This can be used to...
Search fresh public links, source activity, and ready-to-use post angles for Xss.
Fresh curated links around xss are collected here so marketers can spot useful updates and turn timely ideas into posts faster.
Recent items include:
Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.
Originally appeared on RubySec.An authenticated user can create a malicious query that executes arbitrary JavaScript when another user tries to edit the query. This can be used to...
What I Fixed A Cross-Site Scripting (XSS) vulnerability in cyberbro (122 вђ), an open-source OSINT platform. The search highlight feature used .innerHTML with unsanitized user i...
Originally appeared on RubySec.An improper input sanitization vulnerability in the menu node name rendering allows Author-level users to inject stored JavaScript that executes in a...
Originally appeared on RubySec.An improper input sanitization vulnerability in the Page Properties menu node rendering allows Author-level users to inject stored JavaScript that ex...
Originally appeared on RubySec.## Summary There is a possible cross-site scripting vulnerability in rails-html-sanitizer when the sanitizer is configured to allow an SVG reference...
Originally appeared on RubySec.## Summary AlchemyCMS registers its SVG sanitizer (SanitizeSvgJob, a Loofah-based scrubber) only as an after_create_commit callback on Alchemy::Atta...
Originally appeared on RubySec.## Summary Loofah's HTML5 sanitizer restricted only the xlink:href attribute on certain SVG elements to local, same-document references. Browsers al...
A limited CRLF injection flaw can be escalated into a severe HTTP desynchronization attack, poisoning CDN caches and delivering XSS payloads to users on legitimate websites. The at...
Держите открытыми две вкладки. В одной — интернет-банк, куда вы залогинены и где на экране висит ваш баланс. В другой — какой-то сайт, на который вы забрели по ссылке из выдачи, ни...
WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the login scre...
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstra...
With some recent security advisories for Cross Site Scripting (XSS), it feels like an opportune time to remind those who author Twig templates for Drupal:If you're using Twig's |ra...
While React Server Components rely on the custom Flight protocol to stream interactive UIs, this same mechanism introduces powerful deserialization sinks that attackers can exploit...
Originally appeared on RubySec.## Summary Loofah::HTML5::Scrub.allowed_uri? does not correctly reject javascript: or vbscript: URIs when the scheme is split by a numeric character...
Originally appeared on RubySec.## Summary Loofah::HTML5::Scrub.allowed_uri? does not correctly reject javascript: URIs when the scheme is split or prefixed by the HTML5 named char...
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongo...
If you let users publish something, such as a page, prototype, or dashboard, sooner or later you want an "embed this" button so they can drop it into a blog, a portfolio, or docs,...
Project: Drupal coreDate: 2026-July-15Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site scripti...
Project: Drupal coreDate: 2026-July-15Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross-site scriptingAf...
「ブロックの状況を確認できる」とうたうWebサイトへの注意喚起がX上で広がっている。ITmedia NEWS編集部がソースコードを確認したところ、入力したIDとパスワードをそのまま外部のサーバへ送る...
Originally appeared on RubySec.## Description A privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an `HTML block`, and the public...
A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full remote code execution on the...
Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.