<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>appsec.fyi — XSS</title>
  <link>https://appsec.fyi/xss.html</link>
  <description>Curated XSS resources from appsec.fyi</description>
  <language>en-us</language>
  <atom:link href="https://appsec.fyi/feeds/xss.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Thu, 09 Apr 2026 13:57:40 +0000</lastBuildDate>
  <managingEditor>carl@chs.us (Carl Sampson)</managingEditor>
  <item>
    <title>Browser-Based Attacks in 2026: What Every Startup Needs to Know</title>
    <link>https://www.startupdefense.io/blog/browser-based-attacks-2026-startup-guide</link>
    <guid isPermaLink="true">https://www.startupdefense.io/blog/browser-based-attacks-2026-startup-guide</guid>
    <description>Browser-Based Attacks in 2026: What Every Startup Needs to Know</description>
    <category>XSS</category>
    <pubDate>Mon, 06 Apr 2026 02:01:08 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2025-1647: Bootstrap 3 XSS Vulnerability via DOM Clobbering</title>
    <link>https://www.herodevs.com/blog-posts/cve-2025-1647-bootstrap-3-xss-vulnerability-via-dom-clobbering-in-tooltip-and-popover-components</link>
    <guid isPermaLink="true">https://www.herodevs.com/blog-posts/cve-2025-1647-bootstrap-3-xss-vulnerability-via-dom-clobbering-in-tooltip-and-popover-components</guid>
    <description>CVE-2025-1647: Bootstrap 3 XSS Vulnerability via DOM Clobbering</description>
    <category>XSS</category>
    <pubDate>Mon, 06 Apr 2026 02:01:07 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2026-32629: phpMyFAQ XSS Vulnerability</title>
    <link>https://www.sentinelone.com/vulnerability-database/cve-2026-32629/</link>
    <guid isPermaLink="true">https://www.sentinelone.com/vulnerability-database/cve-2026-32629/</guid>
    <description>CVE-2026-32629: phpMyFAQ XSS Vulnerability</description>
    <category>XSS</category>
    <pubDate>Mon, 06 Apr 2026 02:01:05 +0000</pubDate>
  </item>
  <item>
    <title>Cross-site leaks (XS-Leaks) - Security - MDN Web Docs</title>
    <link>https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/XS-Leaks</link>
    <guid isPermaLink="true">https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/XS-Leaks</guid>
    <description>Cross-site leaks (XS-Leaks) - Security - MDN Web Docs</description>
    <category>XSS</category>
    <pubDate>Mon, 06 Apr 2026 02:01:04 +0000</pubDate>
  </item>
  <item>
    <title>Site-DOM-XSS using Cookie Injection: The AI Hackers are Coming</title>
    <link>https://medium.com/@renwa/site-dom-xss-using-cookie-injection-the-ai-hackers-are-coming-faster-than-you-think-3ef82f2a991d</link>
    <guid isPermaLink="true">https://medium.com/@renwa/site-dom-xss-using-cookie-injection-the-ai-hackers-are-coming-faster-than-you-think-3ef82f2a991d</guid>
    <description>Site-DOM-XSS using Cookie Injection: The AI Hackers are Coming</description>
    <category>XSS</category>
    <pubDate>Mon, 06 Apr 2026 02:01:02 +0000</pubDate>
  </item>
  <item>
    <title>Awesome Bug Bounty Writeups - Curated List by Bug Type</title>
    <link>https://github.com/devanshbatham/Awesome-Bugbounty-Writeups</link>
    <guid isPermaLink="true">https://github.com/devanshbatham/Awesome-Bugbounty-Writeups</guid>
    <description>Awesome Bug Bounty Writeups - Curated List by Bug Type</description>
    <category>XSS</category>
    <pubDate>Fri, 03 Apr 2026 15:54:35 +0000</pubDate>
  </item>
  <item>
    <title>XSS Exploit Payloads - DOM, Reflected, Stored, and WAF Bypass</title>
    <link>https://github.com/AkarshYash/Cross-Site-Scripting-XSS--Exploit-Payloads</link>
    <guid isPermaLink="true">https://github.com/AkarshYash/Cross-Site-Scripting-XSS--Exploit-Payloads</guid>
    <description>XSS Exploit Payloads - DOM, Reflected, Stored, and WAF Bypass</description>
    <category>XSS</category>
    <pubDate>Fri, 03 Apr 2026 15:54:34 +0000</pubDate>
  </item>
  <item>
    <title>Stored XSS Vulnerability WAF Bypass Writeup</title>
    <link>https://lopseg.medium.com/bug-bounty-writeup-stored-xss-vulnerability-waf-bypass-f38aae7ff9eb</link>
    <guid isPermaLink="true">https://lopseg.medium.com/bug-bounty-writeup-stored-xss-vulnerability-waf-bypass-f38aae7ff9eb</guid>
    <description>Stored XSS Vulnerability WAF Bypass Writeup</description>
    <category>XSS</category>
    <pubDate>Fri, 03 Apr 2026 15:54:32 +0000</pubDate>
  </item>
  <item>
    <title>Reflected XSS with WAF Bypass — A Creative Payload That Worked</title>
    <link>https://foysal1197.medium.com/reflected-xss-with-waf-bypass-a-creative-payload-that-worked-20e44e9ab23d</link>
    <guid isPermaLink="true">https://foysal1197.medium.com/reflected-xss-with-waf-bypass-a-creative-payload-that-worked-20e44e9ab23d</guid>
    <description>Reflected XSS with WAF Bypass — A Creative Payload That Worked</description>
    <category>XSS</category>
    <pubDate>Fri, 03 Apr 2026 15:54:31 +0000</pubDate>
  </item>
  <item>
    <title>Learn about Cross Site Scripting (XSS) | BugBountyHunter.com</title>
    <link>https://www.bugbountyhunter.com/vulnerability/?type=xss</link>
    <guid isPermaLink="true">https://www.bugbountyhunter.com/vulnerability/?type=xss</guid>
    <description>Learn about Cross Site Scripting (XSS) | BugBountyHunter.com</description>
    <category>XSS</category>
    <pubDate>Fri, 03 Apr 2026 15:54:29 +0000</pubDate>
  </item>
  <item>
    <title>DOM-Based XSS in Single Page Applications (SPAs): A Complete Guide</title>
    <link>https://medium.com/@asifebrahim580/dom-based-xss-in-single-page-applications-spas-a-complete-guide-for-beginners-bug-bounty-56d4e496a0a0</link>
    <guid isPermaLink="true">https://medium.com/@asifebrahim580/dom-based-xss-in-single-page-applications-spas-a-complete-guide-for-beginners-bug-bounty-56d4e496a0a0</guid>
    <description>DOM-Based XSS in Single Page Applications (SPAs): A Complete Guide</description>
    <category>XSS</category>
    <pubDate>Fri, 03 Apr 2026 15:54:27 +0000</pubDate>
  </item>
  <item>
    <title>The Ultimate Guide to Finding and Escalating XSS Bugs | Bugcrowd</title>
    <link>https://www.bugcrowd.com/blog/the-ultimate-guide-to-finding-and-escalating-xss-bugs/</link>
    <guid isPermaLink="true">https://www.bugcrowd.com/blog/the-ultimate-guide-to-finding-and-escalating-xss-bugs/</guid>
    <description>The Ultimate Guide to Finding and Escalating XSS Bugs | Bugcrowd</description>
    <category>XSS</category>
    <pubDate>Fri, 03 Apr 2026 15:54:25 +0000</pubDate>
  </item>
  <item>
    <title>How a Cross-Site Scripting Vulnerability Led to Account Takeover | HackerOne</title>
    <link>https://www.hackerone.com/blog/how-cross-site-scripting-vulnerability-led-account-takeover</link>
    <guid isPermaLink="true">https://www.hackerone.com/blog/how-cross-site-scripting-vulnerability-led-account-takeover</guid>
    <description>How a Cross-Site Scripting Vulnerability Led to Account Takeover | HackerOne</description>
    <category>XSS</category>
    <pubDate>Fri, 03 Apr 2026 15:54:24 +0000</pubDate>
  </item>
  <item>
    <title>XSS Attacks &amp; Exploitation: The Ultimate Guide | YesWeHack</title>
    <link>https://www.yeswehack.com/learn-bug-bounty/xss-attacks-exploitation-ultimate-guide</link>
    <guid isPermaLink="true">https://www.yeswehack.com/learn-bug-bounty/xss-attacks-exploitation-ultimate-guide</guid>
    <description>XSS Attacks &amp; Exploitation: The Ultimate Guide | YesWeHack</description>
    <category>XSS</category>
    <pubDate>Fri, 03 Apr 2026 15:54:22 +0000</pubDate>
  </item>
  <item>
    <title>Cross-Site Scripting (XSS) Cheat Sheet - 2026 Edition | PortSwigger</title>
    <link>https://portswigger.net/web-security/cross-site-scripting/cheat-sheet</link>
    <guid isPermaLink="true">https://portswigger.net/web-security/cross-site-scripting/cheat-sheet</guid>
    <description>Cross-Site Scripting (XSS) Cheat Sheet - 2026 Edition | PortSwigger</description>
    <category>XSS</category>
    <pubDate>Fri, 03 Apr 2026 15:54:21 +0000</pubDate>
  </item>
  <item>
    <title>CISA Warns of Zimbra SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks</title>
    <link>https://thehackernews.com/2026/03/cisa-warns-of-zimbra-sharepoint-flaw.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/03/cisa-warns-of-zimbra-sharepoint-flaw.html</guid>
    <description>CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks https://ift.tt/vwg96OZ</description>
    <category>XSS</category>
    <pubDate>Fri, 03 Apr 2026 01:46:28 +0000</pubDate>
  </item>
  <item>
    <title>Colwen Hotels XSS Hotels launch new collection brand</title>
    <link>https://www.hotelmanagement.net/renovations/colwen-hotels-xss-hotels-redevelop-castle-hotel-launch-new-collection-brand</link>
    <guid isPermaLink="true">https://www.hotelmanagement.net/renovations/colwen-hotels-xss-hotels-redevelop-castle-hotel-launch-new-collection-brand</guid>
    <description>Colwen Hotels, XSS Hotels launch new collection brand https://ift.tt/cbWKXEy</description>
    <category>XSS</category>
    <pubDate>Wed, 01 Apr 2026 13:31:56 +0000</pubDate>
  </item>
  <item>
    <title>ShadowPrompt: Zero-Click Prompt Injection Chain in Anthropics Claude Chrome Extension</title>
    <link>https://socradar.io/blog/shadowprompt-zero-click-anthropics-claude/</link>
    <guid isPermaLink="true">https://socradar.io/blog/shadowprompt-zero-click-anthropics-claude/</guid>
    <description>ShadowPrompt: Zero-Click Prompt Injection Chain in Anthropic’s Claude Chrome Extension https://ift.tt/LQkpR3n</description>
    <category>XSS</category>
    <pubDate>Wed, 01 Apr 2026 06:11:41 +0000</pubDate>
  </item>
  <item>
    <title>Jira Account Takeover</title>
    <link>https://www.esecurityplanet.com/newsletter/cybersecurity-insider/2026-03-31/</link>
    <guid isPermaLink="true">https://www.esecurityplanet.com/newsletter/cybersecurity-insider/2026-03-31/</guid>
    <description>Jira Account Takeover  https://ift.tt/wtHJ6Lm</description>
    <category>XSS</category>
    <pubDate>Wed, 01 Apr 2026 01:11:41 +0000</pubDate>
  </item>
  <item>
    <title>Vulnerabilities in Bludit software</title>
    <link>https://cert.pl/en/posts/2026/03/CVE-2026-25099/</link>
    <guid isPermaLink="true">https://cert.pl/en/posts/2026/03/CVE-2026-25099/</guid>
    <description>Vulnerabilities in Bludit software https://ift.tt/xf0FONS</description>
    <category>XSS</category>
    <pubDate>Tue, 31 Mar 2026 02:31:37 +0000</pubDate>
  </item>
  <item>
    <title>Stored XSS Bug in Jira Work Management Could Lead to Full Organization Takeover</title>
    <link>https://cybersecuritynews.com/stored-xss-bug-in-jira-work-management/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/stored-xss-bug-in-jira-work-management/</guid>
    <description>Stored XSS Bug in Jira Work Management Could Lead to Full Organization Takeover https://ift.tt/chvJTgR</description>
    <category>XSS</category>
    <pubDate>Mon, 30 Mar 2026 15:11:09 +0000</pubDate>
  </item>
  <item>
    <title>Stored XSS Flaw in Jira Work Management Could Enable Full Org Compromise</title>
    <link>https://cyberpress.org/stored-xss-flaw-in-jira-work/</link>
    <guid isPermaLink="true">https://cyberpress.org/stored-xss-flaw-in-jira-work/</guid>
    <description>Stored XSS Flaw in Jira Work Management Could Enable Full Org Compromise https://ift.tt/tBU50wa</description>
    <category>XSS</category>
    <pubDate>Mon, 30 Mar 2026 14:11:54 +0000</pubDate>
  </item>
  <item>
    <title>Stored XSS Vulnerability in Jira Work Management Could Enable Full Organization Takeover</title>
    <link>https://gbhackers.com/stored-xss-vulnerability-in-jira-work-management/</link>
    <guid isPermaLink="true">https://gbhackers.com/stored-xss-vulnerability-in-jira-work-management/</guid>
    <description>Stored XSS Vulnerability in Jira Work Management Could Enable Full Organization Takeover https://ift.tt/NBDfQXj</description>
    <category>XSS</category>
    <pubDate>Mon, 30 Mar 2026 11:16:52 +0000</pubDate>
  </item>
  <item>
    <title>Vulnerabilities in Raytha software</title>
    <link>https://cert.pl/en/posts/2026/03/CVE-2025-69236/</link>
    <guid isPermaLink="true">https://cert.pl/en/posts/2026/03/CVE-2025-69236/</guid>
    <description>Vulnerabilities in Raytha software https://ift.tt/KuydOeU</description>
    <category>XSS</category>
    <pubDate>Sun, 29 Mar 2026 23:01:47 +0000</pubDate>
  </item>
  <item>
    <title>Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website</title>
    <link>https://thehackernews.com/2026/03/claude-extension-flaw-enabled-zero.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/03/claude-extension-flaw-enabled-zero.html</guid>
    <description>Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website https://ift.tt/onyUmWb</description>
    <category>XSS</category>
    <pubDate>Thu, 26 Mar 2026 13:31:50 +0000</pubDate>
  </item>
  <item>
    <title>CISA and FBI release secure-by-design guidelines on cross-site scripting</title>
    <link>https://www.ibm.com/think/news/cisa-fbi-release-secure-by-design-on-cross-site-scripting</link>
    <guid isPermaLink="true">https://www.ibm.com/think/news/cisa-fbi-release-secure-by-design-on-cross-site-scripting</guid>
    <description>CISA and FBI release secure-by-design guidelines on cross-site scripting https://ift.tt/OsAW3Rc</description>
    <category>XSS</category>
    <pubDate>Thu, 26 Mar 2026 11:31:39 +0000</pubDate>
  </item>
  <item>
    <title>HTTP/1.1 Must Die: Conquering the 0.CL Challenge</title>
    <link>https://portswigger.net/blog/http-1-1-must-die-conquering-the-0-cl-challenge</link>
    <guid isPermaLink="true">https://portswigger.net/blog/http-1-1-must-die-conquering-the-0-cl-challenge</guid>
    <description>HTTP/1.1 Must Die: Conquering the 0.CL Challenge https://ift.tt/zWFgsu7</description>
    <category>XSS</category>
    <pubDate>Thu, 26 Mar 2026 09:26:20 +0000</pubDate>
  </item>
  <item>
    <title>CISA Warns of Actively Exploited Zimbra Collaboration Suite Vulnerability</title>
    <link>https://cyberpress.org/zimbra-collaboration-suite-vulnerability/</link>
    <guid isPermaLink="true">https://cyberpress.org/zimbra-collaboration-suite-vulnerability/</guid>
    <description>CISA Warns of Actively Exploited Zimbra Collaboration Suite Vulnerability https://cyberpress.org/zimbra-collaboration-suite-vulnerability/</description>
    <category>XSS</category>
    <pubDate>Thu, 26 Mar 2026 06:26:30 +0000</pubDate>
  </item>
  <item>
    <title>Renaissance Framingham Hotel Debuts After Transformation</title>
    <link>https://lodgingmagazine.com/renaissance-framingham-hotel-conference-center-debuts-after-transformation/</link>
    <guid isPermaLink="true">https://lodgingmagazine.com/renaissance-framingham-hotel-conference-center-debuts-after-transformation/</guid>
    <description>Renaissance Framingham Hotel Debuts After Transformation https://ift.tt/EsDvhRT</description>
    <category>XSS</category>
    <pubDate>Wed, 25 Mar 2026 12:26:47 +0000</pubDate>
  </item>
  <item>
    <title>PolyShell flaw exposes Magento and Adobe Commerce to file upload attacks</title>
    <link>https://securityaffairs.com/189744/security/polyshell-flaw-exposes-magento-and-adobe-commerce-to-file-upload-attacks.html</link>
    <guid isPermaLink="true">https://securityaffairs.com/189744/security/polyshell-flaw-exposes-magento-and-adobe-commerce-to-file-upload-attacks.html</guid>
    <description>PolyShell flaw exposes Magento and Adobe Commerce to file upload attacks https://ift.tt/Vn64pI0</description>
    <category>XSS</category>
    <pubDate>Sat, 21 Mar 2026 10:51:38 +0000</pubDate>
  </item>
  <item>
    <title>Russian APT Exploits Zimbra XSS In GhostMail Attacks On Ukrainian Government</title>
    <link>https://cyberpress.org/ghostmail-targets-ukraine-mail/</link>
    <guid isPermaLink="true">https://cyberpress.org/ghostmail-targets-ukraine-mail/</guid>
    <description>Russian APT Exploits Zimbra XSS In GhostMail Attacks On Ukrainian Government https://cyberpress.org/ghostmail-targets-ukraine-mail/</description>
    <category>XSS</category>
    <pubDate>Fri, 20 Mar 2026 14:16:39 +0000</pubDate>
  </item>
  <item>
    <title>Magento PolyShell Flaw Enables Unauthenticated Uploads RCE and Account Takeover</title>
    <link>https://thehackernews.com/2026/03/magento-polyshell-flaw-enables.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/03/magento-polyshell-flaw-enables.html</guid>
    <description>Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover https://ift.tt/Oxljb9W</description>
    <category>XSS</category>
    <pubDate>Fri, 20 Mar 2026 11:46:47 +0000</pubDate>
  </item>
  <item>
    <title>Russian APT Exploits Zimbra XSS to Target Ukrainian Government in Operation GhostMail</title>
    <link>https://cybersecuritynews.com/russian-apt-exploits-zimbra-xss/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/russian-apt-exploits-zimbra-xss/</guid>
    <description>Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’ https://ift.tt/XoOLnMt</description>
    <category>XSS</category>
    <pubDate>Fri, 20 Mar 2026 06:11:20 +0000</pubDate>
  </item>
  <item>
    <title>Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025-66376</title>
    <link>https://securityaffairs.com/189673/security/russian-apt-targets-ukraine-via-zimbra-xss-flaw-cve-2025-66376.html</link>
    <guid isPermaLink="true">https://securityaffairs.com/189673/security/russian-apt-targets-ukraine-via-zimbra-xss-flaw-cve-2025-66376.html</guid>
    <description>Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025-66376 https://ift.tt/fiP24sx</description>
    <category>XSS</category>
    <pubDate>Thu, 19 Mar 2026 15:56:30 +0000</pubDate>
  </item>
  <item>
    <title>Russian APT Exploits Zimbra Vulnerability Against Ukraine</title>
    <link>https://www.securityweek.com/russian-apt-exploits-zimbra-vulnerability-against-ukraine/</link>
    <guid isPermaLink="true">https://www.securityweek.com/russian-apt-exploits-zimbra-vulnerability-against-ukraine/</guid>
    <description>Russian APT Exploits Zimbra Vulnerability Against Ukraine https://ift.tt/MVsWfZC</description>
    <category>XSS</category>
    <pubDate>Thu, 19 Mar 2026 13:51:12 +0000</pubDate>
  </item>
  <item>
    <title>When HttpOnly Isnt Enough: Chaining XSS and GhostScript for Full RCE Compromise</title>
    <link>https://securityboulevard.com/2026/03/when-httponly-isnt-enough-chaining-xss-and-ghostscript-for-full-rce-compromise/</link>
    <guid isPermaLink="true">https://securityboulevard.com/2026/03/when-httponly-isnt-enough-chaining-xss-and-ghostscript-for-full-rce-compromise/</guid>
    <description>When HttpOnly Isn’t Enough: Chaining XSS and GhostScript for Full RCE Compromise https://ift.tt/aCJHUB2</description>
    <category>XSS</category>
    <pubDate>Wed, 18 Mar 2026 21:06:40 +0000</pubDate>
  </item>
  <item>
    <title>CISA orders feds to patch Zimbra XSS flaw exploited in attacks</title>
    <link>https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-zimbra-xss-flaw-exploited-in-attacks/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-zimbra-xss-flaw-exploited-in-attacks/</guid>
    <description>CISA orders feds to patch Zimbra XSS flaw exploited in attacks https://ift.tt/AV9sfJM</description>
    <category>XSS</category>
    <pubDate>Wed, 18 Mar 2026 20:06:12 +0000</pubDate>
  </item>
  <item>
    <title>Colwen Hotels and XSS Hotels Complete The Framingham Hotel Collection Featuring Three Unique Hotels Revamped Public Spaces and New Culinary Experiences - Travel And Tour World</title>
    <link>https://www.travelandtourworld.com/news/article/colwen-hotels-and-xss-hotels-complete-the-framingham-hotel-collection-featuring-three-unique-hotels-revamped-public-spaces-and-new-culinary-experiences/</link>
    <guid isPermaLink="true">https://www.travelandtourworld.com/news/article/colwen-hotels-and-xss-hotels-complete-the-framingham-hotel-collection-featuring-three-unique-hotels-revamped-public-spaces-and-new-culinary-experiences/</guid>
    <description>Colwen Hotels and XSS Hotels Complete The Framingham Hotel Collection, Featuring Three Unique Hotels, Revamped Public Spaces and New Culinary Experiences - Travel And Tour World https://ift.tt/eJz6Z0L</description>
    <category>XSS</category>
    <pubDate>Tue, 17 Mar 2026 17:36:49 +0000</pubDate>
  </item>
  <item>
    <title>Angular XSS Vulnerability Exposes Thousands of web Applications to XSS Attacks</title>
    <link>https://cybersecuritynews.com/angular-xss-vulnerability-xss-attacks/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/angular-xss-vulnerability-xss-attacks/</guid>
    <description>Angular XSS Vulnerability Exposes Thousands of web Applications to XSS Attacks https://ift.tt/FtpE0RI</description>
    <category>XSS</category>
    <pubDate>Tue, 17 Mar 2026 15:38:14 +0000</pubDate>
  </item>
  <item>
    <title>Angular XSS Vulnerability Puts Thousands of Web Apps at Risk</title>
    <link>https://cyberpress.org/angular-xss-vulnerability/</link>
    <guid isPermaLink="true">https://cyberpress.org/angular-xss-vulnerability/</guid>
    <description>Angular XSS Vulnerability Puts Thousands of Web Apps at Risk https://cyberpress.org/angular-xss-vulnerability/</description>
    <category>XSS</category>
    <pubDate>Tue, 17 Mar 2026 12:05:50 +0000</pubDate>
  </item>
  <item>
    <title>Angular XSS Vulnerability Threatens Thousands of Web Applications</title>
    <link>https://gbhackers.com/angular-xss-vulnerability/</link>
    <guid isPermaLink="true">https://gbhackers.com/angular-xss-vulnerability/</guid>
    <description>Angular XSS Vulnerability Threatens Thousands of Web Applications https://ift.tt/CsxVb9J</description>
    <category>XSS</category>
    <pubDate>Tue, 17 Mar 2026 10:46:26 +0000</pubDate>
  </item>
  <item>
    <title>Persistent XSS/RCE using WebSockets in Storybooks dev server</title>
    <link>https://www.aikido.dev/blog/storybooks-websockets-attack</link>
    <guid isPermaLink="true">https://www.aikido.dev/blog/storybooks-websockets-attack</guid>
    <description>Persistent XSS/RCE using WebSockets in Storybook’s dev server https://ift.tt/FpslaPW</description>
    <category>XSS</category>
    <pubDate>Sat, 14 Mar 2026 10:31:31 +0000</pubDate>
  </item>
  <item>
    <title>Critical 0-Click Microsoft Excel Security Bug Lets Copilot Steal Data</title>
    <link>https://www.forbes.com/sites/daveywinder/2026/03/11/critical-0-click-microsoft-excel-security-bug-lets-copilot-steal-data/</link>
    <guid isPermaLink="true">https://www.forbes.com/sites/daveywinder/2026/03/11/critical-0-click-microsoft-excel-security-bug-lets-copilot-steal-data/</guid>
    <description>Critical 0-Click Microsoft Excel Security Bug Lets Copilot Steal Data https://ift.tt/mTA2R1M</description>
    <category>XSS</category>
    <pubDate>Thu, 12 Mar 2026 13:21:29 +0000</pubDate>
  </item>
  <item>
    <title>GitLab Security Update - Patch for XSS and API DoS Vulnerabilities</title>
    <link>https://cybersecuritynews.com/gitlab-security-update-2/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/gitlab-security-update-2/</guid>
    <description>GitLab Security Update - Patch for XSS and API DoS Vulnerabilities https://ift.tt/WObhDLV</description>
    <category>XSS</category>
    <pubDate>Thu, 12 Mar 2026 10:11:07 +0000</pubDate>
  </item>
  <item>
    <title>1-Click ZITADEL Vulnerability Could Allow Full System Takeover</title>
    <link>https://gbhackers.com/1-click-zitadel-vulnerability/</link>
    <guid isPermaLink="true">https://gbhackers.com/1-click-zitadel-vulnerability/</guid>
    <description>1-Click ZITADEL Vulnerability Could Allow Full System Takeover https://ift.tt/j43WBuo</description>
    <category>XSS</category>
    <pubDate>Mon, 09 Mar 2026 12:36:19 +0000</pubDate>
  </item>
  <item>
    <title>Critical XSS Vulnerability in Angular i18n Enables Malicious Code Execution</title>
    <link>https://cybersecuritynews.com/xss-vulnerability-in-angular-i18n/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/xss-vulnerability-in-angular-i18n/</guid>
    <description>Critical XSS Vulnerability in Angular i18n Enables Malicious Code Execution https://ift.tt/MaisAIy</description>
    <category>XSS</category>
    <pubDate>Wed, 04 Mar 2026 11:01:56 +0000</pubDate>
  </item>
  <item>
    <title>Checkmk and CVE-2025-64999: When a log entry becomes a gateway</title>
    <link>https://www.igorslab.de/en/checkmk-and-cve-2025-64999-when-a-log-entry-becomes-a-gateway/</link>
    <guid isPermaLink="true">https://www.igorslab.de/en/checkmk-and-cve-2025-64999-when-a-log-entry-becomes-a-gateway/</guid>
    <description>Checkmk and CVE-2025-64999: When a log entry becomes a gateway https://ift.tt/7noF219</description>
    <category>XSS</category>
    <pubDate>Wed, 04 Mar 2026 05:16:33 +0000</pubDate>
  </item>
  <item>
    <title>Severe XSS Vulnerability in Angular i18n Enables Malicious Script Injection</title>
    <link>https://cyberpress.org/severe-xss-vulnerability/</link>
    <guid isPermaLink="true">https://cyberpress.org/severe-xss-vulnerability/</guid>
    <description>Severe XSS Vulnerability in Angular i18n Enables Malicious Script Injection https://cyberpress.org/severe-xss-vulnerability/</description>
    <category>XSS</category>
    <pubDate>Tue, 03 Mar 2026 10:46:29 +0000</pubDate>
  </item>
  <item>
    <title>Angular i18n Flaw Lets Hackers Execute Malicious Code via Critical XSS Vulnerability</title>
    <link>https://gbhackers.com/angular-i18n-flaw/</link>
    <guid isPermaLink="true">https://gbhackers.com/angular-i18n-flaw/</guid>
    <description>Angular i18n Flaw Lets Hackers Execute Malicious Code via Critical XSS Vulnerability https://ift.tt/Zxys3rh</description>
    <category>XSS</category>
    <pubDate>Tue, 03 Mar 2026 07:41:41 +0000</pubDate>
  </item>
  <item>
    <title>UK govermnent&#x27;s Vulnerability Monitoring System is working - fixes flow far faster</title>
    <link>https://www.theregister.com/2026/03/02/uk_gov_nips_public_sector/</link>
    <guid isPermaLink="true">https://www.theregister.com/2026/03/02/uk_gov_nips_public_sector/</guid>
    <description>UK govermnent&#x27;s Vulnerability Monitoring System is working - fixes flow far faster https://ift.tt/razAec0</description>
    <category>XSS</category>
    <pubDate>Mon, 02 Mar 2026 03:41:31 +0000</pubDate>
  </item>
</channel>
</rss>