Biggopti: Vulnerable Component in BdThemes Plugins
Biggopti is an internal component shipped with BdThemes plugins that fetches promotional banners from an API server and was vulnerable to XSS…
Biggopti is an internal component shipped with BdThemes plugins that fetches promotional banners from an API server and was vulnerable to XSS…
Sigmative is the API provider whose display_id parameter was exploited in the XSS vulnerability within BdThemes' Biggopti component.
WordPress has released a critical security update to address a pre-authentication reflected cross-site scripting (XSS) vulnerability that affects all versions of the…
CVE-2026-64638 is a pre-authentication reflected XSS vulnerability in WordPress, rated 8.9 on the CVSS scale, that can be exploited to achieve PHP…
pwn.ai, a security research firm, discovered and responsibly disclosed CVE-2026-64638, a pre-authentication XSS vulnerability in WordPress that can lead to PHP code…
HashiCorp, Veeam, and the Django Software Foundation have released patches for 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and…
CVE-2026-15920 is a moderate stored cross-site scripting vulnerability in Django's admin interface where unsafe URLField values could be rendered as links and…
LuCI is the default web-based user interface for OpenWrt. An AI-assisted audit by Hacker House identified multiple vulnerabilities in LuCI components, including…
SpyPress is an obfuscated JavaScript-based malware used by TA458 in Operation RoundPress. It targets webmail platforms including Roundcube, Zimbra, Kerio, SOGo, and…
CVE-2025-66376 is a stored cross-site scripting vulnerability in Zimbra's Classic UI. It was weaponized by the Russia-linked threat actor Laundry Bear to…