Patchstack·21h ago highCross-Site Request Forgery in Elementor Plugin Affecting 2 Million+ Sites#elementor#wordpress#csrf 3 sources 9 min
oss-security·1d agoCVE-2026-82380: Apache Roller: CSRF protection bypass via self-generated salt validation#apache-roller#csrf#cve-2026-82380CVE-2026-82380 17 sources
Lobsters · security·1d agoSourceHut account takeover via build logs (XSS in ansi2html.py)#sourcehut#xss#ansi2htmlVulnerability 3 sources 12 min
BleepingComputer·1d ago highWordPress Click2Shell flaw lets hackers execute PHP on the server#wordpress#click2shell#csrf 6 sources 3 min
CSO Online·2d ago criticalOn-prem VeloCloud Orchestrator under attack, only some versions patched#arista#velocloud#sd-wan 5 sources in the wild 3 min
Cyber Security News·8d ago highClick2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link#click2shell#csrf#exploit-chain 4 min1
Patchstack·8d ago highClick2Shell: The RCE WordPress 7.1.1 Just Patched#click2shell#csrf#jquery 4 min1
The Hacker News·8d ago highNew WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution#click2shell#csrf#patch 3 min2
SANS Internet Storm Center·9d agoHTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)#cache-poisoning#csrf#httpResearch 4 min
CISA Advisories·16d ago highST Engineering iDirect iQ-Series Terminals (Update A)#cisa#csrf#information-disclosureCVE-2026-38059 6 min
CISA Advisories·23d agoTycon Systems TPDIN-Monitor-WEB3#authorization-bypass#cisa#csrfCVE-2026-77847 2 sources 4 min
Security Affairs·Aug 22, 2026 highCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution#ait-gui#ammos#authentication 4 min1
The Hacker News·Aug 20, 2026 highNASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands#ait-gui#csrf#cycode 7 min1
Security Affairs·Aug 18, 2026 highGitLab Patches Critical Unauthenticated GraphQL Vulnerability#csrf#devops#gitlab 2 min1
Help Net Security·Aug 18, 2026 highCritical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)#code-injection#csrf#gitlab1
The Hacker News·Aug 17, 2026 highCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects#csrf#devops#gitlab 2 min1