🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼️CVE-2023-50901‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in HasThemes HT Mega Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega Absolute Addons For Elementor from na through 2.3.8.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-51361‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Ginger Plugins Sticky Chat Widget Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button allows Stored XSS.This issue affects Sticky Chat Widget Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button from na through 1.1.8.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-51371‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Bit Assist Chat Widget WhatsApp Chat, Facebook Messenger Chat, Telegram Chat Bubble, Line Messenger, Live Chat Support Chat Button, WeChat, SMS, Call Button, Customer Support Button with floating Chat Widget allows Stored XSS.This issue affects Chat Widget WhatsApp Chat, Facebook Messenger Chat, Telegram Chat Bubble, Line Messenger, Live Chat Support Chat Button, WeChat, SMS, Call Button, Customer Support Button with floating Chat Widget from na through 1.1.9.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-51372‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in HasThemes HashBar WordPress Notification Bar allows Stored XSS.This issue affects HashBar WordPress Notification Bar from na through 1.4.1.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-51373‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Ian Kennerley Google Photos Gallery with Shortcodes allows Reflected XSS.This issue affects Google Photos Gallery with Shortcodes from na through 4.0.2.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-51374‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in ZeroBounce ZeroBounce Email Verification Validation allows Stored XSS.This issue affects ZeroBounce Email Verification Validation from na through 1.0.11.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-51396‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Brizy.Io Brizy Page Builder allows Stored XSS.This issue affects Brizy Page Builder from na through 2.4.29.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-51397‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Brainstorm Force WP Remote Site Search allows Stored XSS.This issue affects WP Remote Site Search from na through 1.0.4.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-51399‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in WPFactory Back Button Widget allows Stored XSS.This issue affects Back Button Widget from na through 1.6.3.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-51541‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Aleksandar Uroevi? Stock Ticker allows Stored XSS.This issue affects Stock Ticker from na through 3.23.4.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-52135‼️

Improper Neutralization of Special Elements used in an SQL Command 'SQL Injection' vulnerability in WS Form WS Form LITE Drag Drop Contact Form Builder for WordPress.This issue affects WS Form LITE Drag Drop Contact Form Builder for WordPress from na through 1.9.170.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-41813‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Pandora FMS on all allows CrossSite Scripting XSS. Allows you to edit the Web Console user notification options. This issue affects Pandora FMS from 700 through 774.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-41814‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Pandora FMS on all allows CrossSite Scripting XSS. Through an HTML payload iframe tag it is possible to carry out XSS attacks when the user receiving the messages opens their notifications. This issue affects Pandora FMS from 700 through 774.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-41815‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Pandora FMS on all allows CrossSite Scripting XSS. Malicious code could be executed in the File Manager section. This issue affects Pandora FMS from 700 through 774.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-44088‼️

Improper Neutralization of Special Elements used in an SQL Command 'SQL Injection' vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS from 700 through 774.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-44089‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Pandora FMS on all allows CrossSite Scripting XSS. It was possible to execute malicious JS code on Visual Consoles. This issue affects Pandora FMS from 700 through 774.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50837‼️

Improper Neutralization of Special Elements used in an SQL Command 'SQL Injection' vulnerability in WebFactory Ltd Login Lockdown Protect Login Form.This issue affects Login Lockdown Protect Login Form from na through 2.06.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50879‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Automattic WordPress.Com Editing Toolkit allows Stored XSS.This issue affects WordPress.Com Editing Toolkit from na through 3.78784.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50880‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in The BuddyPress Community BuddyPress allows Stored XSS.This issue affects BuddyPress from na through 11.3.1.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50881‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in AAM Advanced Access Manager Restricted Content, Users Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager Restricted Content, Users Roles, Enhanced Security and More from na through 6.9.15.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50889‼️

Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in The Beaver Builder Team Beaver Builder WordPress Page Builder allows Stored XSS.This issue affects Beaver Builder WordPress Page Builder from na through 2.7.2.

📖 Read more

Via "National Vulnerability Database"