The vulnerability allowed unauthorized disclosure of private email addresses of WakaTime users through the private leaderboards feature. The email addresses were exposed to leaderboard creators and me ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
The reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" input field of the Cost Tracker section in MainWP (Version 5.4.0.11). Arbitrary user input in thi ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function sendEmailCode of the file src/main/java/co/yiiu/pybbs/controller/api/SettingsApiCont ...
Continue ReadingAugust 05, 2025
The image upload endpoint in the Lichess application did not properly validate the 'rel' parameter, allowing an attacker to inject special characters that broke the expected format of the ge ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
Back to Main