The reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" input field of the Cost Tracker section in MainWP (Version 5.4.0.11). Arbitrary user input in thi ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
The SCIM provisioning feature in HackerOne's sandbox program was vulnerable to account takeover. An attacker could create a user with an email they controlled, import existing users, assign the v ...
Continue ReadingAugust 05, 2025
A critical vulnerability was identified in the Firefox Accounts API that allowed an authenticated attacker to permanently delete any user's account by sending a POST /v1/account/destroy request u ...
Continue ReadingAugust 05, 2025
The WordPress CMS version was exposed in the XML file at https://hemi.xyz███. This disclosure allowed attackers to fingerprint the CMS...Read More ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
Back to Main