1Roundcube Webmail: three more sanitizer bypasses enable tracking and phishing (opens in new tab)(nullcathedral.com)2nullcathedral7d ago1
2Perfex CRM: Unauthenticated RCE via PHP's S: deserialization format (opens in new tab)(nullcathedral.com)1nullcathedral10d ago1
3Roundcube Webmail: SVG feImage bypasses image blocking to track email opens (opens in new tab)(nullcathedral.com)175nullcathedral1mo ago75