The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
More Stories
mysql8.0-8.0.41-1.fc41
FEDORA-2025-8352a35e30 Packages in this update: mysql8.0-8.0.41-1.fc41 Update description: MySQL 8.0.41 Reease notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-41.html Read More
mysql8.0-8.0.41-1.fc40
FEDORA-2025-ebdcfc0f27 Packages in this update: mysql8.0-8.0.41-1.fc40 Update description: MySQL 8.0.41 Reease notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-41.html Read More
workrave-1.11.0~rc.1-1.el9
FEDORA-EPEL-2025-85c41364aa Packages in this update: workrave-1.11.0~rc.1-1.el9 Update description: Unretireing the package. Read More
workrave-1.11.0~rc.1-1.fc41
FEDORA-2025-d611c8d114 Packages in this update: workrave-1.11.0~rc.1-1.fc41 Update description: Unretireing the package. Read More
workrave-1.11.0~rc.1-1.fc42
FEDORA-2025-85867bd98f Packages in this update: workrave-1.11.0~rc.1-1.fc42 Update description: Unretireing the package. Read More
workrave-1.11.0~rc.1-1.fc40
FEDORA-2025-2d5726abb8 Packages in this update: workrave-1.11.0~rc.1-1.fc40 Update description: Unretireing the package. Read More