[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting
A reflected cross-site scripting flaw in Bludit CMS 3.20.0 is documented with a public proof-of-concept exploit on Exploit-DB.
Exploit-DB published exploit ID 52678 targeting Bludit CMS 3.20.0, a web application affected by reflected cross-site scripting. The listing contains a proof-of-concept but includes no CVE identifier or evidence of active exploitation.
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Cisco patched a reflected XSS in the ISE management interface allowing unauthenticated attackers to execute script via crafted links.
A reflected cross-site scripting vulnerability in the web-based management interface of Cisco Identity Services Engine lets an unauthenticated remote attacker execute arbitrary script in the context of the interface. Exploitation requires persuading a user to click a crafted link due to improper input validation. Cisco has released software updates.
[20260801] - Core - Response header injection in download views
Joomla fixes CVE-2026-71572, response header injection in download views enabling reflected file download attacks, in 5.4.8/6.1.3.
Joomla disclosed a response header injection flaw (CVE-2026-71572) in multiple download views, caused by lack of output processing, enabling reflected file download and content-type confusion. It is rated low impact, severity, and probability and affects Joomla CMS 3.0.0-5.4.7 and 6.0.0-6.1.2. The fix ships in Joomla 5.4.8 and 6.1.3 on 2026-08-18.