Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > Cross-Site Scripting
#Cross-Site Scripting

MapLibre Sanitizer Bug Puts 2.7 Million Sites at Risk of Zero-Click Code Execution

10 September 2026  |  dark6  |  Vulnerability

A critical flaw in the widely used MapLibre GL JS mapping library lets attackers slip malicious event handlers past its HTML sanitizer, triggering code execution with no clicks...

>> read more

New WordPress Flaw Turns a Failed Login Attempt Into Full Server Takeover

9 August 2026  |  dark6  |  Vulnerability

A newly disclosed WordPress vulnerability, dubbed XSS2Shell and tracked as CVE-2026-64638, chains a decade-old parsing quirk in the login page into full remote code execution, putting an estimated...

>> read more