1Roundcube Webmail: three more sanitizer bypasses enable tracking and phishing (opens in new tab)(nullcathedral.com)2nullcathedral3mo ago1Save
2Perfex CRM: Unauthenticated RCE via PHP's S: deserialization format (opens in new tab)(nullcathedral.com)1nullcathedral3mo ago1Save
3Roundcube Webmail: SVG feImage bypasses image blocking to track email opens (opens in new tab)(nullcathedral.com)175nullcathedral4mo ago75Save