๐ฐ Cross Site Scripting News
Page 5 - Cross Site Scripting News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Cross Site Scripting. Real-time updates on events, politics, business and more.
May 25, 2023
# Exploit Title: FusionInvoice 2023-1.0 - Stored XSS (Cross-Site Scripting)# Date: 2023-05-24# Exploit Author: Andrea Intilangelo# Vendor Homepage: https://www.squarepiginteractive.com# Software Link: https://www.fusioninvoice.com/store# Version: 2023-1.0# Tested on: Latest Version of Desktop Web Browsers (ATTOW: Firefox 113.0.1, Microsoft Edge 113.0.1774.50)# CVE: CVE-2023-25439Description:A stored cross-site scripting (XSS) vulnerability in FusionInvoice 2023-1.0 (from Sqware Pig, LLC) allows ...
May 23, 2023
W3 Eden recently patched an Authenticated Stored Cross-Site Scripting vulnerability in Download Manager.On April 25, 2023, our Wordfence Threat Intelligence team identified and began the responsible disclosure process for a stored Cross-Site Scripting (XSS) vulnerability in W3 Edenโs Download Manager plugin, which is actively installed on more than 100,000 WordPress websites, making it one of
May 22, 2023
MonsterInsights Google Analytics WordPress plugin XSS vulnerability affects up to +3 million websites
May 20, 2023
# Exploit Title: CiviCRM 5.59.alpha1 - Stored XSS (Cross-Site Scripting)# Date: 2023-02-02# Exploit Author: Andrea Intilangelo# Vendor Homepage: https://civicrm.org# Software Link: https://civicrm.org/download# Version: 5.59.alpha1, 5.58.0 (and earlier), 5.57.3 (and earlier)# Tested on: Latest Version of Desktop Web Browsers (ATTOW: Firefox 109.0.1, Microsoft Edge 109.0.1518.70)# CVE: CVE-2023-25440 / Vendor Security Advisory: CIVI-SA-2023-05Description:A stored cross-site scripting (XSS)
May 17, 2023
On May 16, 2023, the WordPress core team released WordPress 6.2.1, which contains patches for 5 vulnerabilities, including a Medium Severity Directory Traversal vulnerability, a Medium-Severity Cross-Site Scripting vulnerability, and several lower-severity vulnerabilities.These patches have been backported to every version of WordPress since 4.1. WordPress has supported automatic core updates for security releases since WordPress
May 5, 2023
A recently discovered WordPress bug weakens users' content management systems and can make website visitors vulnerable to cyberattacks.
April 25, 2023
Affected Plugin: Shield Security โ Smart Bot Blocking & Intrusion Prevention Plugin Slug: wp-simple-firewallAffected Versions:
April 13, 2023
On January 26, 2023, the Wordfence team responsibly disclosed an unauthenticated stored Cross-Site Scripting vulnerability in Limit Login Attempts, a WordPress plugin installed on over 600,000 sites that provides site owners with the ability to block IP addresses that have made repeated failed login attempts.The plugin is vulnerable in versions up to, and including, 1.7.1.
April 12, 2023
San Francisco, CA (PRWEB) April 12, 2023 -- Cobalt, the Pentest as a Service (PtaaS) company that is modernizing the manual pentesting model, today announced
April 5, 2023
This article describes three additional vulnerabilities discovered and responsibly disclosed by the SonarSource R&D team in GoCD 21.2.0.