7hecoder.medium.com
Cross-Site Scripting Explained: Protect Your Website from Modern Threats
Cross-Site Scripting (XSS): Protect your site from XSS attacks. Learn how to write secure code and defend your business from potential breaches in 2024.
#XSS is an active hashtag on Bluesky. In the last 30 days, 19 people shared 34 posts with it — around 1 a day. Activity is up 133% versus the previous week, peaking on Jul 11 with 9 posts.
Tags most often used together with #XSS.
7hecoder.medium.com
Cross-Site Scripting Explained: Protect Your Website from Modern Threats
Cross-Site Scripting (XSS): Protect your site from XSS attacks. Learn how to write secure code and defend your business from potential breaches in 2024.
github.com
GitHub - ronin-rb/ronin-vulns: Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side Template Injection (SSTI), an...
Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects. - ronin-rb...
medium.com
My First XSS Vulnerability. The Day I Started My Bug Bounty Journey
Introduction:
thehackernews.com
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.
eslammsd-mobile-games-zone.static.hf.space
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Mobile Games Zone
dlvr.it
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,
wordpress.donweb.com
WordPress 7.0.3: qué corrige y por qué actualizar ya
Release de seguridad del 6 de agosto de 2026: 7 vulnerabilidades corregidas, con un XSS pre-auth crítico. Cómo actualizar paso a paso.
thehackernews.com
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.
eslammsd-mobile-games-zone.static.hf.space
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Mobile Games Zone
dlvr.it
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,
wordpress.donweb.com
WordPress 7.0.3: qué corrige y por qué actualizar ya
Release de seguridad del 6 de agosto de 2026: 7 vulnerabilidades corregidas, con un XSS pre-auth crítico. Cómo actualizar paso a paso.
securityonline.info
CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution
TL;DR WordPress 7.0.3 is out as a security release. This WordPress security update fixes about a dozen flaws. The most serious is CVE-2026-64638, a pre-auth cross-site scripting bug that can escalate to remote code execution. It scores 8.9. Update your sites right away. Why it matters WordPress powers a large share of the web. A pre-auth flaw needs no login to start.
www.heise.de
Russische Akteure greifen über Outlook-Web-Access-Lücke an
Eine Sicherheitslücke in OWA ermöglicht durch Anzeigen von Mails das Ausführen von JavaScript-Code. Russische Akteure nutzen das aus.
mastodon.social
Original post on mastodon.social
www.heise.de
OpenWrt: Updates schließen teils kritische Sicherheitslücken
Das OpenWrt-Projekt hat aktualisierte Fassungen veröffentlicht, die teils als kritisches Risiko eingestufte Sicherheitslücken stopfen.
thehackernews.com
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Russian hackers exploit CVE-2026-42897 in OWA to deploy OWAReaper, a browser implant that persists through credential rotation and device re-imaging.
mastodon.social
Original post on mastodon.social
Posts are pulled live from Bluesky and cached briefly. Posts with content labels are hidden.