<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #XSS</title><description>Cybersecurity articles tagged #XSS on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>BdThemes WordPress Plugin Supply Chain Attack Creates Rogue Admins</title><link>https://runtimerebel.com/blog/bdthemes-wordpress-plugin-supply-chain-attack-creates-rogue-admins</link><guid isPermaLink="true">https://runtimerebel.com/blog/bdthemes-wordpress-plugin-supply-chain-attack-creates-rogue-admins</guid><description>A supply chain attack on BdThemes WordPress plugins exploited an XSS vulnerability, creating stealthy rogue admin accounts and webshells.</description><pubDate>Tue, 11 Aug 2026 08:45:01 GMT</pubDate><category>WordPress</category><category>Supply Chain Attack</category><category>XSS</category><category>Webshell</category><category>BdThemes</category></item><item><title>CVE-2026-64638: WordPress Pre-Auth XSS Leads to PHP RCE</title><link>https://runtimerebel.com/blog/cve-2026-64638-wordpress-pre-auth-xss-leads-to-php-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-64638-wordpress-pre-auth-xss-leads-to-php-rce</guid><description>A pre-authentication reflected XSS (CVE-2026-64638) in WordPress can be chained for PHP code execution. Patch immediately.</description><pubDate>Fri, 07 Aug 2026 16:42:22 GMT</pubDate><category>WordPress</category><category>XSS</category><category>RCE</category><category>Web Security</category><category>CVE-2026-64638</category></item><item><title>Zimbra Classic Web Client XSS: Critical Flaw Under Active Exploit</title><link>https://runtimerebel.com/blog/zimbra-classic-web-client-xss-critical-flaw-under-active-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-classic-web-client-xss-critical-flaw-under-active-exploit</guid><description>A critical XSS vulnerability in Zimbra Classic Web Client is under active exploitation, allowing credential theft and session hijacking.</description><pubDate>Fri, 10 Jul 2026 14:31:43 GMT</pubDate><category>Zimbra</category><category>XSS</category><category>Classic Web Client</category><category>Zimbra Collaboration Suite</category><category>Active Exploitation</category></item><item><title>WordPress Sites Targeted via Kirki and Burst Statistics Vulnerabilities</title><link>https://runtimerebel.com/blog/wordpress-sites-targeted-via-kirki-and-burst-statistics-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-sites-targeted-via-kirki-and-burst-statistics-vulnerabilities</guid><description>Attackers are exploiting unauthenticated stored XSS in Kirki and Burst Statistics plugins to achieve privilege escalation and website takeover.</description><pubDate>Wed, 03 Jun 2026 13:48:48 GMT</pubDate><category>CVE-2024-11884</category><category>CVE-2024-11046</category><category>WordPress</category><category>Kirki</category><category>Burst Statistics</category><category>XSS</category><category>Privilege Escalation</category></item><item><title>CVE-2021-22291: ABB EIBPORT V3 &lt;3.9.2 Session Hijacking Vulnerability</title><link>https://runtimerebel.com/blog/cve-2021-22291-abb-eibport-v3-3-9-2-session-hijacking-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2021-22291-abb-eibport-v3-3-9-2-session-hijacking-vulnerability</guid><description>ABB EIBPORT V3 devices are vulnerable to CVE-2021-22291 (XSS/session hijacking), allowing unauthenticated access and configuration changes. Patch immediately.</description><pubDate>Thu, 28 May 2026 17:27:09 GMT</pubDate><category>CVE-2021-22291</category><category>ABB EIBPORT</category><category>XSS</category><category>Session Hijacking</category><category>ICS</category><category>Building Automation</category><category>Critical Manufacturing</category></item><item><title>CVE-2024-50498: CISA Orders Patch for Exploited cPanel Plugin Flaw</title><link>https://runtimerebel.com/blog/cve-2024-50498-cisa-orders-patch-for-exploited-cpanel-plugin-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-50498-cisa-orders-patch-for-exploited-cpanel-plugin-flaw</guid><description>CISA mandates federal agencies patch CVE-2024-50498, an actively exploited LiteSpeed cPanel plugin vulnerability, to prevent unauthorized account access.</description><pubDate>Wed, 27 May 2026 13:21:58 GMT</pubDate><category>CVE-2024-50498</category><category>cPanel</category><category>LiteSpeed</category><category>CISA KEV</category><category>XSS</category></item><item><title>CVE-2026-4293: Kieback &amp; Peter DDC XSS — Mitigate Building Controller Risks</title><link>https://runtimerebel.com/blog/cve-2026-4293-kieback-peter-ddc-xss-mitigate-building-controller-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-4293-kieback-peter-ddc-xss-mitigate-building-controller-risks</guid><description>CISA warns of CVE-2026-4293, a Cross-site Scripting vulnerability in Kieback &amp; Peter DDC Building Controllers.</description><pubDate>Tue, 19 May 2026 20:43:11 GMT</pubDate><category>Kieback Peter</category><category>DDC Building Controllers</category><category>CVE-2026-4293</category><category>XSS</category><category>Cross Site Scripting</category><category>ICS</category><category>OT Security</category><category>Building Automation</category><category>CWE-79</category></item><item><title>CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day Under Attack</title><link>https://runtimerebel.com/blog/cve-2026-42897-microsoft-exchange-owa-xss-zero-day-under-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42897-microsoft-exchange-owa-xss-zero-day-under-attack</guid><description>Active Zero-Day XSS vulnerability, CVE-2026-42897, impacts Microsoft Exchange OWA, allowing mailbox compromise. No patch available.</description><pubDate>Tue, 19 May 2026 00:57:54 GMT</pubDate><category>CVE-2026-42897</category><category>Microsoft Exchange</category><category>OWA</category><category>XSS</category><category>Zero-Day</category><category>Outlook Web Access</category></item><item><title>CVE-2026-42897: Microsoft Exchange XSS Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-42897-microsoft-exchange-xss-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42897-microsoft-exchange-xss-under-active-exploitation</guid><description>CISA adds CVE-2026-42897, a Microsoft Exchange Server Cross-Site Scripting vulnerability, to KEV Catalog due to active exploitation. Immediate patching advised.</description><pubDate>Fri, 15 May 2026 20:32:11 GMT</pubDate><category>CVE-2026-42897</category><category>Microsoft Exchange Server</category><category>Cross Site Scripting</category><category>XSS</category><category>CISA KEV</category><category>Active Exploitation</category></item><item><title>CVE-2026-42897: How Attackers Exploit Microsoft Exchange Server</title><link>https://runtimerebel.com/blog/cve-2026-42897-how-attackers-exploit-microsoft-exchange-server</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42897-how-attackers-exploit-microsoft-exchange-server</guid><description>Microsoft warns of active exploitation of CVE-2026-42897, a critical spoofing and XSS vulnerability in on-premise Exchange Server triggered via email.</description><pubDate>Fri, 15 May 2026 09:11:29 GMT</pubDate><category>CVE-2026-42897</category><category>Microsoft Exchange Server</category><category>XSS</category><category>Spoofing</category><category>Zero-Day</category></item><item><title>CVE-2023-29489: How Attackers Exploit cPanel XSS for Auth Bypass</title><link>https://runtimerebel.com/blog/cve-2023-29489-how-attackers-exploit-cpanel-xss-for-auth-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-29489-how-attackers-exploit-cpanel-xss-for-auth-bypass</guid><description>A critical authentication bypass in cPanel via CVE-2023-29489 is under active exploitation. Discover technical details and essential mitigation steps.</description><pubDate>Mon, 04 May 2026 20:36:54 GMT</pubDate><category>cPanel</category><category>CVE-2023-29489</category><category>Authentication Bypass</category><category>XSS</category><category>Web Hosting</category></item><item><title>Zimbra XSS Attacks: Over 10,000 Servers Vulnerable — Patch Now</title><link>https://runtimerebel.com/blog/zimbra-xss-attacks-over-10000-servers-vulnerable-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-xss-attacks-over-10000-servers-vulnerable-patch-now</guid><description>Ongoing cross-site scripting (XSS) attacks exploit a flaw in Zimbra Collaboration Suite (ZCS), leaving over 10,000 online servers vulnerable.</description><pubDate>Fri, 24 Apr 2026 16:28:18 GMT</pubDate><category>Zimbra</category><category>ZCS</category><category>XSS</category><category>Cross Site Scripting</category><category>Email Server</category><category>Vulnerability</category></item><item><title>Claude Chrome Extension Zero-Click Prompt Injection Vulnerability</title><link>https://runtimerebel.com/blog/claude-chrome-extension-zero-click-prompt-injection-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-chrome-extension-zero-click-prompt-injection-vulnerability</guid><description>A critical flaw in Anthropic&apos;s Claude Chrome extension allowed websites to silently inject malicious prompts using zero-click XSS techniques.</description><pubDate>Thu, 26 Mar 2026 16:31:26 GMT</pubDate><category>Anthropic</category><category>Claude</category><category>Prompt Injection</category><category>Browser Extension</category><category>XSS</category></item><item><title>CVE-2025-13902: Patching Schneider Electric Modicon Controllers</title><link>https://runtimerebel.com/blog/cve-2025-13902-patching-schneider-electric-modicon-controllers</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-13902-patching-schneider-electric-modicon-controllers</guid><description>Schneider Electric Modicon M241 and M251 controllers face XSS risks via CVE-2025-13902. Learn how to patch firmware and secure industrial control networks.</description><pubDate>Thu, 19 Mar 2026 16:26:40 GMT</pubDate><category>CVE-2025-13902</category><category>Schneider Electric</category><category>Modicon</category><category>ICS</category><category>XSS</category></item><item><title>CVE-2025-66376: ZCS Cross-Site Scripting Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2025-66376-zcs-cross-site-scripting-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-66376-zcs-cross-site-scripting-actively-exploited</guid><description>CISA adds CVE-2025-66376, a Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting vulnerability, to its KEV Catalog due to active exploitation.</description><pubDate>Wed, 18 Mar 2026 20:18:10 GMT</pubDate><category>CVE-2025-66376</category><category>Synacor Zimbra Collaboration Suite</category><category>ZCS</category><category>XSS</category><category>Known Exploited Vulnerabilities</category><category>CISA KEV</category></item><item><title>CVE-2024-4510: Zimbra Collaboration Suite XSS Exploitation Guide</title><link>https://runtimerebel.com/blog/cve-2024-4510-zimbra-collaboration-suite-xss-exploitation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-4510-zimbra-collaboration-suite-xss-exploitation-guide</guid><description>CISA adds CVE-2024-4510 to the KEV catalog following active exploitation of a Zimbra Collaboration Suite XSS vulnerability. Patch ZCS version 9.0.0 today.</description><pubDate>Wed, 18 Mar 2026 20:16:14 GMT</pubDate><category>CVE-2024-4510</category><category>Zimbra</category><category>XSS</category><category>CISA KEV</category><category>Mail Security</category></item><item><title>Exploitation of SVG-Based XSS in RoundCube Webmail Instances</title><link>https://runtimerebel.com/blog/exploitation-of-svg-based-xss-in-roundcube-webmail-instances</link><guid isPermaLink="true">https://runtimerebel.com/blog/exploitation-of-svg-based-xss-in-roundcube-webmail-instances</guid><description>Technical analysis of a cross-site scripting (XSS) vulnerability in RoundCube Webmail triggered by improper sanitization of SVG animate elements.</description><pubDate>Mon, 23 Feb 2026 12:23:45 GMT</pubDate><category>Roundcube</category><category>XSS</category><category>SVG</category><category>Webmail Security</category></item><item><title>Exploitation of Roundcube Webmail Cross-Site Scripting Vulnerabilities</title><link>https://runtimerebel.com/blog/exploitation-of-roundcube-webmail-cross-site-scripting-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/exploitation-of-roundcube-webmail-cross-site-scripting-vulnerabilities</guid><description>CISA has added two Roundcube Webmail vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling active exploitation of legacy flaws in webmail…</description><pubDate>Mon, 23 Feb 2026 12:20:44 GMT</pubDate><category>Roundcube</category><category>XSS</category><category>CISA</category><category>KEV</category><category>Webmail</category></item></channel></rss>