Security News

XSS Vulnerability Exposed Google Employees to Attacks
2019-06-13 13:01

A researcher revealed on Wednesday that he discovered a blind cross-site scripting (XSS) vulnerability that could have been exploited to attack Google employees and possibly gain access to...

WordPress WP Live Chat Support Plugin Fixes XSS Flaw
2019-05-17 19:28

A cross-site scripting flaw in a popular WordPress plugin enables an unauthenticated attacker to insert JavaScript payloads into impacted websites.

JavaScript Library Introduced XSS Flaw in Google Search
2019-04-01 18:35

A change made several months ago in an open-source JavaScript library introduced a cross-site scripting (XSS) vulnerability in Google Search and likely other Google products. read more

WordPress 5.1.1 patches dangerous XSS vulnerability
2019-03-18 10:54

Researchers have offered more detail on a recently patched vulnerability that would allow an attacker to take over a WordPress site.

Don't be a WordPress RCE-hole and patch up this XSS vuln, pronto
2019-03-14 18:02

Not on 5.1.1? You should be A newly revealed vuln in the open-source CMS WordPress allows an unauthenticated website attacker to remotely execute code – potentially letting naughty folk delete or...

Researcher Earns $10,000 for Another XSS Flaw in Yahoo Mail
2019-02-22 07:14

A researcher says he has discovered yet another critical cross-site scripting (XSS) vulnerability in Yahoo Mail. The recently patched flaw could have been exploited to steal the targeted user’s...

Serious XSS flaw discovered in Evernote for Windows, update now!
2018-11-07 12:36

Online-note-sharing company Evernote has patched a hole that allowed attackers to infect notes shared via its service.

Recent Branch.io Patch Creates New XSS Flaw
2018-10-22 16:35

The patch for a recently disclosed cross-site scripting (XSS) vulnerability in Branch.io introduced another similar flaw, a security researcher revealed last week. read more

Branch.io Flaws Exposed Tinder, Shopify, Yelp Users to XSS Attacks
2018-10-15 05:13

Hundreds of millions of users may have been exposed to cross-site scripting (XSS) attacks due to a vulnerability present in Branch.io, a service used by Tinder, Shopify, Yelp and many others. read more

D-Link Patches Code Execution, XSS Flaws in Management Tool
2018-10-05 10:26

D-Link has released patches for several remote code execution and cross-site scripting (XSS) vulnerabilities found by researchers in the company's Central WiFiManager access point management tool....