Daily Writeups
3.53K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Unauthenticated RCE in BeyondTrust Tools: Chat Feature Opens Door to Server Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 17 Jun 2025 00:30:13 +0000
════════════════════════
Tags: #Vulnerability #BeyondTrust #Chat Feature #cybersecurity #PRA #Privileged Remote Access #rce #Remote Code Execution #Remote Support #Server Side Template Injection #ssti
Title: CVE-2025-53833 (CVSS 10): Critical SSTI Flaw in LaRecipe Threatens Millions of Laravel Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 15 Jul 2025 02:01:46 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2025_53833 #cybersecurity #Laravel #LaRecipe #php #rce #Remote Code Execution #Server Side Template Injection #ssti #Vulnerability #web framework
Title: Lab 1: Basic server-side template injection (Server-side template injection)
════════════════════════
𐀪 Author: L4V4NY4 AGR3
════════════════════════
Time: Thu, 06 Nov 2025 12:23:43 GMT
════════════════════════
Tags: #server_side_injection #server_side_template #burpsuite #portswigger_lab #ssrf
Title: CVE-2026-25526: Critical Jinjava Flaw (CVSS 9.8) Permits Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 09 Feb 2026 00:21:47 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_25526 #ForTag Vulnerability #HubSpot CMS #Java Template Engine #Jinjava #ObjectMapper Deserialization #Patch Alert #Remote Code Execution #Sandbox Escape #Server Side Template Injection
Title: Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 17 Apr 2026 13:30:29 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_40477 #CVE_2026_40478 #infosec #Java security #Patch Alert #rce #Server Side Template Injection #Spring Security #ssti #Thymeleaf #web development
Title: Critical 9.0 CVSS Flaw in Thymeleaf Enables Remote Server Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 06 May 2026 12:38:06 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_41901 #cybersecurity #infosec #Java security #Patch Alert #rce #Sandbox Bypass #Server Side Template Injection #ssti #Thymeleaf #web development
Title: Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 21 May 2026 01:01:23 +0000
════════════════════════
Tags: #Vulnerability Report #Apache OFBiz #Authentication Bypass #CVE_2026_31378 #CVE_2026_45434 #Cyber Security #infosec #JSON Attribute Manipulation #Patch Alert #Remote Code Execution #Server Side Template Injection #ssti