What broke this week · Area

Advisories as they were published, beside the people writing about them and the rules the internet just agreed on. This is the filing, not the fix: nothing here tells you whether you are affected.

Latest

Fake CAPTCHA ScamsBruce Schneierschneier.com25 Years of Mass Surveillance Is EnoughBruce Schneierschneier.comOn the NSA’s Supercomputer from the 1960sBruce Schneierschneier.comUpcoming Speaking EngagementsBruce Schneierschneier.comUsing AI for Weapons DevelopmentBruce Schneierschneier.comMicrosoft’s PatchingBruce Schneierschneier.comFriday Squid Blogging: Rotting Squid on a Beached California BoatBruce Schneierschneier.comMy Talk at DEF CONBruce Schneierschneier.comCliff Stoll’s DEF CON TalkBruce Schneierschneier.comCVE-2026-18562The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insufficient input sanitization and output escaping in the wp_load_js() function, which reads filter values from the URL path via the url_request extension's parse_url_query() and embeds them into an inline JavaScript string using json_encode() without escaping single quotes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.nist.govCVE-2026-18579The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce failure path for the getshortcodedrenderedfenodelay action serves as the log-write trigger rather than an access barrier — a deliberately failed nonce check causes wppa_log() to record the attacker-supplied X-Forwarded-For value to disk, making the exploit fully reachable by unauthenticated callers via the wp_ajax_nopriv_wppa endpoint.nist.govCVE-2026-18964The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. WordPress's server-side HTML encoding of the 's' search parameter in the <title> element is bypassed because the browser DOM API decodes HTML entities when jQuery's .text() method reads document.title, returning literal special characters that are then embedded unescaped into the constructed HTML attribute value.nist.gov

More

  1. CVE-2026-12215nist.gov
  2. CVE-2026-15462nist.gov
  3. CVE-2026-18561nist.gov
  4. CVE-2026-11496nist.gov
  5. CVE-2026-11446nist.gov
  6. CVE-2026-88260nist.gov
  7. CVE-2026-89151nist.gov
  8. CVE-2026-78135nist.gov
  9. CVE-2026-88914nist.gov
  10. CVE-2026-89092nist.gov
  11. CVE-2026-89145nist.gov
  12. CVE-2026-78127nist.gov
  13. CVE-2026-78129strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.nist.gov
  14. CVE-2026-78130nist.gov
  15. CVE-2026-78131nist.gov
  16. CVE-2026-78132nist.gov
  17. CVE-2026-78133nist.gov
  18. CVE-2026-78134nist.gov
  19. CVE-2026-78123nist.gov
  20. CVE-2026-78124nist.gov
  21. CVE-2026-78126nist.gov
  22. CVE-2026-84941nist.gov
  23. CVE-2026-81905nist.gov
  24. CVE-2026-81906nist.gov
  25. CVE-2026-77807nist.gov
  26. CVE-2026-18121nist.gov
  27. CVE-2026-17176nist.gov
  28. Supreme Court forces TV stations to sell more election ads at steep discountsarstechnica.com
  29. Top chipmakers embrace ASML’s $400M machines, agree to crucial chipmaking changearstechnica.com
  30. Godzilla Minus Zero IMAX trailer teases King Ghidoraharstechnica.com