Cross-Site Scripting
Injection into rendered markup: the sanitiser that missed, the sink that executed, and the impact.
Published work on this topic
| 2026-08-21 | CVE-2026-55674 | CVE-2026-55674: Discourse Cache Poisoning XSS | PoC | |
| 2026-08-15 | CVE-2019-10349 | CVE-2019-10349: Jenkins Dependency Graph - Stored XSS | PoC | |
| 2026-08-10 | CVE-2026-71285 | CVE-2026-71285: Uptime Kuma Matomo Stored XSS | PoC | |
| 2026-08-07 | CVE-2026-64638 | CVE-2026-64638: WordPress XSS2Shell Pre-Auth RCE | PoC |
Other topics
remote code execution38authentication bypass19wordpress14php13authorization bypass9java9path traversal9sql injection8privilege escalation7code injection6denial of service6heap overflow6insecure deserialization5information disclosure5qemu5apache tomcat4go4node.js4python4buffer overflow3gitea3gitlab3javascript3
