The report identifies a bypass vulnerability in the biography field on addons.allizom.org. Despite the application's policy against allowing links, it was possible to embed functional hyperlinks ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
The reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" input field of the Cost Tracker section in MainWP (Version 5.4.0.11). Arbitrary user input in thi ...
Continue ReadingAugust 05, 2025
A path traversal vulnerability was discovered in the Lila project that allowed an attacker to access arbitrary files on the server by manipulating user-supplied input to traverse outside the intended ...
Continue ReadingAugust 05, 2025
An incomplete fix has been identified for a vulnerability affecting Windows device names in the path.normalize() function in Node.js. The vulnerability allows path traversal protection to be bypassed ...
Continue ReadingAugust 05, 2025
Back to Main