Daily Writeups
3.56K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Understanding XML and XXE vulnerabilities
════════════════════════
𐀪 Author: Sadineni Sai Sushanth
════════════════════════
Time: Mon, 01 Sep 2025 12:10:56 GMT
════════════════════════
Tags: #pentesting #ethical_hacking #xml_external_entities #cybersecurity #web_security
Title: Lab 18 : SQL injection with filter bypass via XML encoding
════════════════════════
𐀪 Author: L4V4NY4 AGR3
════════════════════════
Time: Tue, 28 Oct 2025 05:59:50 GMT
════════════════════════
Tags: #sql_query_in_xml #xml_sqlite #sql_injection #xml_sql_injection #hackvector_burp_ext
Title: CVE-2025–59287: When WSUS turns from a trusted patch server into an attacker launchpad
════════════════════════
𐀪 Author: Rabbit Knight
════════════════════════
Time: Wed, 29 Oct 2025 23:19:09 GMT
════════════════════════
Tags: #w3wp #xml_soap #cve_2025_59287 #wsu #rce
Title: High-Severity GeoServer Flaw (CVE-2025-58360) Allows Unauthenticated XXE for File Theft and SSRF
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 01 Dec 2025 00:22:33 +0000
════════════════════════
Tags: #Vulnerability Report #Critical Vulnerability #File Exfiltration #GeoServer #ssrf #unauthenticated #WMS GetMap #XML External Entity #xxe
Title: CRITICAL ALERT: Apache Tika XXE Flaw (CVSS 10.0) Allows File Read via PDF Files
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 09 Dec 2025 03:15:32 +0000
════════════════════════
Tags: #Vulnerability #Apache Tika #CVE_2025_66516 #Patch Now #PDF Parser #Security Advisory #SSRF #Tika_core #XML External Entity #XXE
Title: Critical Authentication Bypass Flaws Discovered in Ruby SAML Library (CVE-2025-66567 & CVE-2025-66568)
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 09 Dec 2025 02:29:23 +0000
════════════════════════
Tags: #Vulnerability Report #Authentication Bypass #Canonicalization #CVE_2025_66567 #Digest Bypass #Ruby SAML #XML Parser Differential
Title: CISA KEV Alert: GeoServer XXE Flaw Under Active Attack Risks Data Theft & Internal Network Scanning
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 12 Dec 2025 03:00:51 +0000
════════════════════════
Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58360 #Data Theft #GeoServer #ssrf #XML External Entity #xxe
Title: Forging the Keys: Inside SAMLSmith, the C# Framework for Golden & Silver SAML Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 24 Dec 2025 03:08:48 +0000
════════════════════════
Tags: #Open Source Tool #Active Directory #Cybersecurity 2025 #Entra ID #Golden SAML #Identity Security #Pentesting #SAML #SAMLSmith #Silver SAML #XML Forgery
Title: Apache SIS Patch Blocks XML Attack That Leaks Server Files
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 06 Jan 2026 02:07:54 +0000
════════════════════════
Tags: #Vulnerability Report #Apache SIS #Apache Software Foundation #CVE_2025_68280 #Geospatial Security #GeoTIFF #GML #GPX #Information Disclosure #Java security #Metadata Security #XML Injection #xxe
Title: High-Severity DoS Flaw Hits 46 Million ‘fast-xml-parser’ Downloads
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 19 Feb 2026 14:17:42 +0000
════════════════════════
Tags: #Vulnerability Report #Billion Laughs Attack #CVE_2026_26278 #Denial of Service #dos #Event Loop #fast_xml_parser #Node.js Security #npm Package #Patch Alert #XML parsing
Title: XML Injection & XXE: From Confusion to Exploitation
════════════════════════
𐀪 Author: Aman Gupta
════════════════════════
Time: Mon, 20 Apr 2026 10:47:27 GMT
════════════════════════
Tags: #web_application_security #api_security #cybersecurity #xml_injection_xxe #bug_bounty_hunting
Title: The File That Answered Back — XXE Hidden in Cell A2
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
Time: Tue, 21 Apr 2026 17:05:28 GMT
════════════════════════
Tags: #xml #bug_bounty_writeup #bug_bounty #file_upload_vulnerability #xxe
Title: Workflow Warning: The n8n CVSS 10.0 Prototype Pollution Crisis
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 24 Apr 2026 12:01:16 +0000
════════════════════════
Tags: #Vulnerability Report #Automation #CVSS 10 #infosec #JavaScript Security #n8n #Node.js #Patch Alert #Prototype Pollution #rce #Webhook Security #XML parsing
Title: The File That Answered Back — XXE Hidden in Cell A2
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
Time: Mon, 06 Jul 2026 06:28:59 GMT
════════════════════════
Tags: #xml #bug_bounty_writeup #bug_bounty #file_upload_vulnerability #xxe