⤷ Title: Understanding XML and XXE vulnerabilities
════════════════════════
𐀪 Author: Sadineni Sai Sushanth
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 12:10:56 GMT
════════════════════════
⌗ Tags: #pentesting #ethical_hacking #xml_external_entities #cybersecurity #web_security
════════════════════════
𐀪 Author: Sadineni Sai Sushanth
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 12:10:56 GMT
════════════════════════
⌗ Tags: #pentesting #ethical_hacking #xml_external_entities #cybersecurity #web_security
Medium
Understanding XML and XXE vulnerabilities
Introduction
⤷ Title: Lab 18 : SQL injection with filter bypass via XML encoding
════════════════════════
𐀪 Author: L4V4NY4 AGR3
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 05:59:50 GMT
════════════════════════
⌗ Tags: #sql_query_in_xml #xml_sqlite #sql_injection #xml_sql_injection #hackvector_burp_ext
════════════════════════
𐀪 Author: L4V4NY4 AGR3
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 05:59:50 GMT
════════════════════════
⌗ Tags: #sql_query_in_xml #xml_sqlite #sql_injection #xml_sql_injection #hackvector_burp_ext
Medium
Lab 18 : SQL injection with filter bypass via XML encoding
This lab contains a SQL injection vulnerability in its stock check feature. The results from the query are returned in the application’s…
⤷ Title: CVE-2025–59287: When WSUS turns from a trusted patch server into an attacker launchpad
════════════════════════
𐀪 Author: Rabbit Knight
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 23:19:09 GMT
════════════════════════
⌗ Tags: #w3wp #xml_soap #cve_2025_59287 #wsu #rce
════════════════════════
𐀪 Author: Rabbit Knight
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 23:19:09 GMT
════════════════════════
⌗ Tags: #w3wp #xml_soap #cve_2025_59287 #wsu #rce
Medium
CVE-2025–59287: When WSUS turns from a trusted patch server into an attacker launchpad
In cybersecurity, the worst-case sometimes is a simple one: a trusted internal system (the one you rely on to push updates ) is turned…
⤷ Title: High-Severity GeoServer Flaw (CVE-2025-58360) Allows Unauthenticated XXE for File Theft and SSRF
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:22:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #File Exfiltration #GeoServer #ssrf #unauthenticated #WMS GetMap #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:22:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #File Exfiltration #GeoServer #ssrf #unauthenticated #WMS GetMap #XML External Entity #xxe
Daily CyberSecurity
High-Severity GeoServer Flaw (CVE-2025-58360) Allows Unauthenticated XXE for File Theft and SSRF
GeoServer patched a High-severity XXE flaw (CVE-2025-58360, CVSS 8.2) in its WMS GetMap operation. The flaw allows unauthenticated remote attackers to read arbitrary files and perform SSRF. Update to v2.27.0.
⤷ Title: CRITICAL ALERT: Apache Tika XXE Flaw (CVSS 10.0) Allows File Read via PDF Files
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:15:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apache Tika #CVE_2025_66516 #Patch Now #PDF Parser #Security Advisory #SSRF #Tika_core #XML External Entity #XXE
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:15:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apache Tika #CVE_2025_66516 #Patch Now #PDF Parser #Security Advisory #SSRF #Tika_core #XML External Entity #XXE
Penetration Testing Tools
CRITICAL ALERT: Apache Tika XXE Flaw (CVSS 10.0) Allows File Read via PDF Files
On 4 December 2025, the Apache Software Foundation disclosed a critical vulnerability — CVE-2025-66516, rated the maximum CVSS
⤷ Title: Critical Authentication Bypass Flaws Discovered in Ruby SAML Library (CVE-2025-66567 & CVE-2025-66568)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 02:29:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Canonicalization #CVE_2025_66567 #Digest Bypass #Ruby SAML #XML Parser Differential
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 02:29:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Canonicalization #CVE_2025_66567 #Digest Bypass #Ruby SAML #XML Parser Differential
Daily CyberSecurity
Critical Authentication Bypass Flaws Discovered in Ruby SAML Library (CVE-2025-66567 & CVE-2025-66568)
A pair of critical security vulnerabilities has been disclosed in the Ruby SAML library, a foundational tool used by developers to implement client-side SAML authorization. Both flaws carry a crit…
⤷ Title: CISA KEV Alert: GeoServer XXE Flaw Under Active Attack Risks Data Theft & Internal Network Scanning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:00:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58360 #Data Theft #GeoServer #ssrf #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:00:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58360 #Data Theft #GeoServer #ssrf #XML External Entity #xxe
Daily CyberSecurity
CISA KEV Alert: GeoServer XXE Flaw Under Active Attack Risks Data Theft & Internal Network Scanning
CISA added a critical XXE flaw (CVE-2025-58360) in OSGeo GeoServer to the KEV Catalog. The actively exploited bug allows attackers to read arbitrary files and perform SSRF on internal networks. Patch immediately.
⤷ Title: Forging the Keys: Inside SAMLSmith, the C# Framework for Golden & Silver SAML Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 03:08:48 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #Cybersecurity 2025 #Entra ID #Golden SAML #Identity Security #Pentesting #SAML #SAMLSmith #Silver SAML #XML Forgery
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 03:08:48 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #Cybersecurity 2025 #Entra ID #Golden SAML #Identity Security #Pentesting #SAML #SAMLSmith #Silver SAML #XML Forgery
Information Security News
Forging the Keys: Inside SAMLSmith, the C# Framework for Golden & Silver SAML Attacks
SAMLSmith is a C# tool for generating custom SAML responses and implementing Silver SAML and Golden SAML attacks. It provides comprehensive functionality for security researchers and penetration t…
⤷ Title: Apache SIS Patch Blocks XML Attack That Leaks Server Files
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 02:07:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache SIS #Apache Software Foundation #CVE_2025_68280 #Geospatial Security #GeoTIFF #GML #GPX #Information Disclosure #Java security #Metadata Security #XML Injection #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 02:07:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache SIS #Apache Software Foundation #CVE_2025_68280 #Geospatial Security #GeoTIFF #GML #GPX #Information Disclosure #Java security #Metadata Security #XML Injection #xxe
Daily CyberSecurity
Apache SIS Patch Blocks XML Attack That Leaks Server Files
The Apache Software Foundation has issued a security advisory for the Apache Spatial Information System (SIS), a key Java library used for developing geospatial applications. A newly discovered vu…
⤷ Title: High-Severity DoS Flaw Hits 46 Million ‘fast-xml-parser’ Downloads
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 14:17:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Billion Laughs Attack #CVE_2026_26278 #Denial of Service #dos #Event Loop #fast_xml_parser #Node.js Security #npm Package #Patch Alert #XML parsing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 14:17:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Billion Laughs Attack #CVE_2026_26278 #Denial of Service #dos #Event Loop #fast_xml_parser #Node.js Security #npm Package #Patch Alert #XML parsing
Daily CyberSecurity
High-Severity DoS Flaw Hits 46 Million 'fast-xml-parser' Downloads
Node.js DoS flaw CVE-2026-26278 in fast-xml-parser freezes event loops via XML entity expansion. 46M weekly downloads affected. Update to version 5.3.6.
⤷ Title: XML Injection & XXE: From Confusion to Exploitation
════════════════════════
𐀪 Author: Aman Gupta
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 10:47:27 GMT
════════════════════════
⌗ Tags: #web_application_security #api_security #cybersecurity #xml_injection_xxe #bug_bounty_hunting
════════════════════════
𐀪 Author: Aman Gupta
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 10:47:27 GMT
════════════════════════
⌗ Tags: #web_application_security #api_security #cybersecurity #xml_injection_xxe #bug_bounty_hunting
⤷ Title: The File That Answered Back — XXE Hidden in Cell A2
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 17:05:28 GMT
════════════════════════
⌗ Tags: #xml #bug_bounty_writeup #bug_bounty #file_upload_vulnerability #xxe
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 17:05:28 GMT
════════════════════════
⌗ Tags: #xml #bug_bounty_writeup #bug_bounty #file_upload_vulnerability #xxe
Medium
The File That Answered Back — XXE Hidden in Cell A2
Most people know XXE. Few think to look for it inside a spreadsheet upload. But beneath every .xlsx is really a ZIP archive full of XML…
⤷ Title: Workflow Warning: The n8n CVSS 10.0 Prototype Pollution Crisis
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 12:01:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Automation #CVSS 10 #infosec #JavaScript Security #n8n #Node.js #Patch Alert #Prototype Pollution #rce #Webhook Security #XML parsing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 12:01:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Automation #CVSS 10 #infosec #JavaScript Security #n8n #Node.js #Patch Alert #Prototype Pollution #rce #Webhook Security #XML parsing
Daily CyberSecurity
Workflow Warning: The n8n CVSS 10.0 Prototype Pollution Crisis
Critical CVSS 10 and 9.4 vulnerabilities hit n8n. Prototype pollution in XML nodes can lead to full RCE. Patch to v2.18.1 or v1.123.32 immediately.
⤷ Title: The File That Answered Back — XXE Hidden in Cell A2
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 06:28:59 GMT
════════════════════════
⌗ Tags: #xml #bug_bounty_writeup #bug_bounty #file_upload_vulnerability #xxe
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 06:28:59 GMT
════════════════════════
⌗ Tags: #xml #bug_bounty_writeup #bug_bounty #file_upload_vulnerability #xxe
Medium
The File That Answered Back — XXE Hidden in Cell A2
Most people know XXE. Few think to look for it inside a spreadsheet upload. But beneath every .xlsx is really a ZIP archive full of XML…