CryptoCat

@cryptocat.me

Security Researcher @rapid7.com 😈 Hacking Content @ https://yt.cryptocat.me 💜

Another Essential Addons bug.. with a much smaller bounty! 😁 A Contributor could poison the site-wide Reading Progress bar with JavaScript. Once their post was published, moving over the bar on an unrelated page ran the payload in the visitor's session. cryptocat.me/blog/researc...

Essential Addons for Elementor Global Reading Progress Stored XSS | CVE-2026-15156 | CryptoCat's Blog

Root cause analysis of CVE-2026-15156 in Essential Addons for Elementor Lite, where a Contributor-controlled Reading Progress colour is stored globally and rendered without escaping, causing stored XS...

cryptocat.me

We've launched a new free Web Security Academy topic on exploiting AI-powered security scanners! Learn how to use indirect prompt injection to steal data, cause damage & trigger exploit chains! Dive in here: portswigger.net/web-security...

AI-powered scanner vulnerabilities | Web Security Academy

Application security teams often deploy AI-powered scanners that use Large Language Models (LLMs) to scan web applications for vulnerabilities. While ...

portswigger.net