Anwendungssicherheit
ANWENDUNGSSICHERHEIT
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript...
🟡 CVE-2026-11968: Medium Schwachstelle
Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit
🟡 CVE-2026-8905: Medium Schwachstelle
The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
🟡 CVE-2026-8628: Medium Schwachstelle
The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and...
🟡 CVE-2026-8622: Medium Schwachstelle
The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all...
🟡 CVE-2026-9620: Medium Schwachstelle
The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post...
🟡 CVE-2026-8896: Medium Schwachstelle
The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other...
🟡 CVE-2026-8865: Medium Schwachstelle
The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in...
🟡 CVE-2026-11370: Medium Schwachstelle
The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,...
🟡 CVE-2025-71332: Medium Luecke in Flowiseai Flowise
Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value,...