Aggregator
CVE-2025-7648 | Ruven Themes Plugin up to 1.0 on WordPress Shortcode ruven_button cross site scripting
CVE-2025-6781 | Copymatic Plugin up to 2.1 on WordPress Setting copymatic_apikey cross-site request forgery
CVE-2025-6053 | Zuppler Online Ordering Plugin up to 2.1.0 on WordPress Setting cross-site request forgery
CVE-2025-7763 | thinkgem JeeSite up to 5.12.0 Site Controller SiteController.java select redirect (Issue 28 / EUVD-2025-21826)
CVE-2025-6335 | DedeCMS up to 5.7.2 Template dedetag.class.php notes command injection
Grafana Flaws Allow User Redirection and Code Execution in Dashboards
Grafana Labs has released critical security patches addressing two significant vulnerabilities that could enable attackers to redirect users to malicious websites and execute arbitrary code within dashboard environments. The security update addresses CVE-2025-6023, a high-severity cross-site scripting (XSS) vulnerability, and CVE-2025-6197, a medium-severity open redirect flaw, both discovered through the company’s bug bounty program. Critical […]
The post Grafana Flaws Allow User Redirection and Code Execution in Dashboards appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Threat Actors Weaponizing GitHub Accounts To Host Payloads, Tools and Amadey Malware Plug-Ins
A sophisticated Malware-as-a-Service operation has emerged that exploits the trusted GitHub platform to distribute malicious payloads, representing a significant evolution in cybercriminal tactics. The operation leverages fake GitHub accounts to host an arsenal of malware tools, plugins, and payloads, capitalizing on GitHub’s widespread corporate acceptance to bypass traditional web filtering mechanisms. The malicious campaign targets […]
The post Threat Actors Weaponizing GitHub Accounts To Host Payloads, Tools and Amadey Malware Plug-Ins appeared first on Cyber Security News.