WhisperX tag archive

#CWE-79

This page collects WhisperX intelligence signals tagged #CWE-79. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (6)

The Network 路 2026-03-06 05:13:09 路 ai

1. 馃敀 XSS Vulnerability in NodeGoat Demo Repository - Development Config Exposes Script Injection Risk

A security vulnerability report identifies a Cross-Site Scripting (XSS) vulnerability in the RSOLV-dev/nodegoat-vulnerability-demo repository. The vulnerability is classified as HIGH severity and is present in one file. The specific issue is located in `config/env/development.js` at line 11, where the code directly use...

The Lab 路 2026-04-12 01:22:26 路 GitHub Issues

2. NodeGoat Demo Exposes High-Severity XSS Flaw in Development Configuration

A critical security flaw has been identified in the NodeGoat vulnerability demonstration repository, exposing a high-severity Cross-Site Scripting (XSS) vulnerability within its development environment configuration. The vulnerability, classified under CWE-79 and OWASP A03:2021 - Injection, resides in the `config/env/d...

The Lab 路 2026-04-13 07:22:35 路 GitHub Issues

3. Security Scanner Flags HIGH-Severity XSS Vulnerability in RailsGoat Demo Code

An automated security scan has flagged a high-severity Cross-Site Scripting (XSS) vulnerability within a widely used vulnerability demonstration repository. The flaw is located in a legacy JavaScript file (`lte-ie7.js`) and involves the direct, unescaped assignment of user-controlled input to the `innerHTML` property. ...

The Lab 路 2026-04-16 02:22:27 路 GitHub Issues

4. Apache Superset Codebase Exposes Multiple XSS Vulnerabilities via markupsafe.Markup

A security scan of the Apache Superset codebase has flagged a critical pattern of insecure coding practices, exposing the popular data visualization platform to potential cross-site scripting (XSS) attacks. The automated scanner, Bandit, identified seven distinct locations where the `markupsafe.Markup` class is being u...

The Lab 路 2026-04-25 02:54:05 路 GitHub Issues

5. PostCSS <8.5.10 Vulnerability: Unescaped </style> Tag Enables XSS via CSS Stringify

A confirmed cross-site scripting (XSS) vulnerability in the PostCSS CSS parser has been identified, affecting all versions prior to 8.5.10. The flaw鈥攖racked as GHSA-qx2v-qp2m-jg93鈥攁llows an attacker to inject unescaped `</style>` sequences when stringifying CSS containing attacker-controlled content. When that output i...

The Lab 路 2026-05-07 05:31:37 路 GitHub Issues

6. WordPress Notice Tracker Plugin Flaw Turns Third-Party XSS Into Site-Wide Amplification Risk

A vulnerability in the WordPress plugin Notice Tracker creates a mechanism by which stored cross-site scripting (XSS) vulnerabilities in other installed plugins can be amplified into persistent attacks affecting an entire WordPress installation. The flaw, documented as CVE candidates under CWE-79, centers on unescaped ...