#Self-Xss
broke: self retweeting tweet with XSS

woke: self reposting post with ROP
January 7, 2024 at 12:42 AM
SafeLine est un WAF (Web Application Firewall) open source sous licence GPL v3. Il est conçu pour protéger contre des attaques type xss, injection sql, injection crlf, etc ... Et dispose de tout ce qui est nécessaire (gui, plugins, ...) ⬇️

github.com/chaitin/Safe...
GitHub - chaitin/SafeLine: SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits. - chaitin/SafeLine
github.com
October 19, 2025 at 6:32 AM
📢 New #updates · 1 Oct #8.2

· Fider v0.38.1 — Fixed XSS vulnerability and updated dependencies

More self-hosted updates → https://selfhost.directory

#privacymatters #passwords #api #cli
October 1, 2026 at 8:40 AM
SuiteCRM scores a D trust grade. 49 CVEs, max CVSS 10, and 95% of issues still unpatched. SQL injection and XSS dominate. Self-hosted CRM means patching is on you. https://www.valtersit.com/vendors/suitecrm/ #cybersecurity #SuiteCRM
Suitecrm
www.valtersit.com
October 2, 2026 at 3:00 PM
Do you intend to write it up as a blog post? Unfortunately, it’s not self-explanatory with slides? I am curious:) ps: Reminds me of frederikbraun.de/xss-digital-....
XSS in The Digital #ClimateStrike Widget
XSS in The Digital #ClimateStrike Widget
frederikbraun.de
May 24, 2025 at 5:25 PM
This month, @0x999.net made an awesome and difficult Intigriti XSS challenge. I really enjoyed the openness of this challenge resulting in an unintended solution and the first solve 🩸!
Check out how I got there in my writeup below:
jorianwoltjer.com/blog/p/hacki...
Intigriti March XSS Challenge (0325) | Jorian Woltjer
A hard Cross-Site Scripting challenge chaining small bugs with one very hard step to leak a fragment directive using Self XSS
jorianwoltjer.com
April 2, 2025 at 6:51 AM
We tested another mail client, Roundcube this time. The agents found a Stored Self-XSS vulnerability that could really only be exploited with Cookie Tossing.
Scary for password reset tokens...
Blog post below:
www.aikido.dev/blog/roundcu...
Roundcube XSS chained with cookie tossing for full inbox access
We found a stored XSS in Roundcube's draft attachment endpoint that, chained with a cookie tossing technique, gives an attacker full access to a victim's inbox. Here's how the exploit chain works and ...
www.aikido.dev
April 21, 2026 at 4:38 PM
The Hidden XSS: A Bug Hidden in the Mist
The Hidden XSS: A Bug Hidden in the Mist
From Subdomain Chaos to an Unexpected XSS A beginner’s bug bounty journey that led to a hidden Self-XSS on Paytm, with the help of some…
infosecwriteups.com
April 13, 2025 at 3:50 PM
AI-generated · n8n shipped fixes for a Sep 30 advisory batch (RCE via Git node, SQLi, HMAC approval bypass, stored XSS). Self‑hosters: move to 1.123.83 / 2.41.4 / 2.42.1 now, then hunt for unusual executions, new credentials, and webhook spikes.
n8n security advisories (Sep 30, 2026): Which versions should self‑hosters patch to now, and what should they check?
n8n published a batch of security advisories on Sep 30, 2026; fixes are available in 1.123.83, 2.42.1, and 2.41.4. Self‑hosted and automation teams should upgrade immediately and review logs, credentials, and webhooks for abuse indicators.
kira-ai.de
October 1, 2026 at 6:01 PM
Cloudflare leaked 10% of bot traffic to my homelab. Installed SafeLine WAF via Docker in 5 minutes. Free, self-hosted, blocks SQLi, XSS, DDoS. Guide: https://www.valtersit.com/guides/security/safeline-waf-docker-homelab-api-protection/ #homelab #docker #security
September 27, 2026 at 7:30 AM
🏃👈 That's you running to our YouTube because a new video just dropped.

bronxi is here to show you 3️⃣ ways to escalate your xss bugs to the next level, using reflected xss and self xss!

Hit play and share with a friend who loves hunting for xss. 😈 youtu.be/0C9c-4hWi0Q?...
Elevate the severity of your xss
YouTube video by Bugcrowd
youtu.be
January 30, 2025 at 4:21 PM
December 31, 2025 at 11:09 PM
Self-hosted photo and video backup solution Immich has released version 1.127, adding manual face tagging, memory enhancements, star rating search, and improved external library management. It also fixes a cross-site scripting (XSS) vulnerability.
https://buff.ly/41iKROP
February 27, 2025 at 10:31 AM
Make Self-XSS Great Again
Make Self-XSS Great Again
blog.slonser.info
June 14, 2025 at 10:24 AM
This is an interesting post, but I'm hung up on how insane the predicate for this vulnerability is: "developer points Cursor with full MCP SQL access at untrusted content". This isn't "lethal trifecta". It already has a name: self-XSS.

simonwillison.net/2025/Jul/6/s...
Supabase MCP can leak your entire SQL database
Here's yet another example of a lethal trifecta attack, where an LLM system combines access to private data, exposure to potentially malicious instructions and a mechanism to communicate data back …
simonwillison.net
July 8, 2025 at 8:09 PM
GitLab Security Update – Patch for XSS and API DoS Vulnerabilities
GitLab Security Update – Patch for XSS and API DoS Vulnerabilities
GitLab has released urgent security updates for its Community Edition (CE) and Enterprise Edition (EE) to address a wide range of vulnerabilities. The newly released versions 18.9.2, 18.8.6, and 18.7.6 fix a total of 15 security issues, including critica l Cross-Site Scripting (XSS) and Denial-of-Service (DoS) flaws. Administrators of self-managed instances are strongly urged to apply these patches immediately to maintain good security hygiene and protect their environments.​ GitLab Vulnerabilities Patched The most critical issue addressed in this release is CVE-2026-1090, a high-severity XSS vulnerability with a CVSS score of 8.7. This flaw exists in GitLab’s Markdown placeholder processing when the Markdown placeholders feature flag is enabled. An authenticated attacker can bypass proper sanitization checks to inject malicious JavaScript into a victim’s browser, potentially leading to unauthorized actions or session hijacking. Additionally, GitLab patched three high-severity DoS vulnerabilities that could allow unauthenticated attackers to disrupt critical services. A flaw in the GraphQL API allows specially crafted requests to cause uncontrolled recursion and resource exhaustion. Malicious requests sent to the repository archive endpoints can also trigger a denial-of-service attack under specific conditions. Furthermore, improper validation of JSON payloads in the protected branches API can be easily exploited to crash the service. Beyond the high-severity issues, this update resolves several medium and low-severity bugs. Notable fixes include addressing DoS risks in webhook custom headers (CVE-2025-13690) and webhook endpoints (CVE-2025-12576). The patch also neutralizes  improper CRLF sequences (CVE-2026-3848) and fixes access control issues in the runners API (CVE-2025-12555), which could have allowed unauthorized access to previous pipeline job information. Information disclosure bugs affecting confidential issues were also successfully remediated. The security update addresses several specific CVEs that administrators should track. CVE-2026-1090 is a high-severity cross-site scripting flaw in Markdown placeholder processing with a CVSS score of 8.7. There are also three high-severity denial-of-service vulnerabilities, each with a CVSS score of 7.5: CVE-2026-1069 affects the GraphQL API, CVE-2025-13929 impacts the repository archive endpoint, and CVE-2025-14513 targets the protected branches API. Furthermore, the patch resolves two medium-severity denial-of-service issues, both scoring 6.5 on the CVSS scale, involving webhook custom headers (CVE-2025-13690) and the webhook endpoint (CVE-2025-12576). To ensure continuous service and data protection, organizations must take immediate action. Update all self-managed GitLab CE and EE installations to versions 18.9.2, 18.8.6, or 18.7.6. Single-node instances will experience brief downtime during the upgrade as database migrations complete. In contrast, multi-node setups can utilize zero-downtime upgrade procedures. Users on GitLab.com and GitLab Dedicated are already running the patched versions and require no administrative action. Detailed vulnerability reports will be made public on GitLab’s issue tracker 30 days after this patch release. Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories. The post GitLab Security Update – Patch for XSS and API DoS Vulnerabilities appeared first on Cyber Security News .
cybersecuritynews.com
March 12, 2026 at 7:44 AM
Ah, self-xss
June 26, 2023 at 8:20 AM
AI-generated · n8n posted 10 security advisories (mostly High) on Sep 30. Patches: 1.123.83, 2.41.4, 2.42.1. Self‑hosters: patch exposed prod first, then validate Git node/agent/webhook use and consider credential rotation. n8n Cloud is patched per the vendor.
n8n security advisories (Sep 30, 2026): Which high‑ and moderate‑severity flaws were fixed, and which releases should self‑hosters install now?
n8n published ten GitHub security advisories on Sep 30, 2026, including High‑severity items such as Git node code execution, an HMAC approval bypass, SQL injection, stored XSS, and an owner‑takeover via prototype mutation; patched builds 1.123.83, 2.41.4, and 2.42.1 are available. Self‑hosters shoul
kira-ai.de
October 5, 2026 at 6:27 PM
CVE-2026-104479 - Shopclass before 6.2.0 Stored XSS via Listing Description Field
CVE ID : CVE-2026-104479

Published : Oct. 3, 2026, 12:16 a.m. | 46 minutes ago

Description : Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-reg...
CVE-2026-104479 - Shopclass before 6.2.0 Stored XSS via Listing Description Field
Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the …
cvefeed.io
October 3, 2026 at 1:45 AM
youtu.be/Y35OwVQH2KE

Author created a video showing how to build your own Blind XSS detection server using AI — fully self-hosted, deployable on your personal machine or even the cloud for free, and ready within minutes.
Create Your Own Blind XSS Detection Server with These Simple Steps
YouTube video by BePractical
youtu.be
March 23, 2026 at 2:31 AM
The impact of #Self-Xss Same-Site Same-origin Explained | self cross site scripting

youtu.be/dFLcykwzN58
The impact of Self-Xss Same-Site Same-origin Explained | self cross site scripting
YouTube video by WebWonders
youtu.be
November 17, 2025 at 1:12 PM
ID: CVE-2024-32468
CVSS V3.1: MEDIUM
Deno is a runtime for JavaScript and TypeScript written in rust. Several cross-site scripting vulnerabilities existed in the `deno_doc` crate which lead to Self-XSS with deno doc --html. 1.) XSS in generated `search_index.js`,...
#security #infosec #cve-alert
nvd.nist.gov
November 25, 2024 at 7:27 PM