#XSS
AI-Powered Pentest Uncovers Eight Security Holes in Popular NodeBB Forum Software
A whitebox penetration test assisted by AI tools found eight high-severity flaws in the NodeBB forum platform, including bugs that could let attackers read private messages, hijack admin...
CISA Warns of Actively Exploited Microsoft Exchange Server XSS Flaw — Patch by May 29
CISA has added CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange Server's Outlook Web Access, to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild....
GitLab Releases Critical Security Patch for Multiple High-Severity Vulnerabilities
Security researchers have uncovered vulnerabilities in GitLab’s Community Edition and Enterprise Edition platforms, prompting the company to release critical security patches. On December 10th, 2025, Gitlab released update...