Stored Cross-Site Scripting in Media Manager of TastyIgniter
Vulnerability in the Media Manager of TastyIgniter allowing Stored XSS. Coordinated and published via official INCIBE advisory, with a dedicated public PoC repository.
JF / 2026 Independent discovery of vulnerabilities in production software, each managed through coordinated disclosure with the vendor and INCIBE.
Vulnerability in the Media Manager of TastyIgniter allowing Stored XSS. Coordinated and published via official INCIBE advisory, with a dedicated public PoC repository.
Independently identified a critical LPE vulnerability in a widely deployed corporate backup solution. The flaw allows a low-privileged user to escalate to SYSTEM on affected hosts. Patch under development with vendor.
Remote Code Execution vulnerability in the add-on upload functionality of a school management platform. Vendor and product name withheld while disclosure is coordinated directly.
An information disclosure vulnerability in a gym management platform: a misconfigured access-control file, written in syntax unsupported by the deployed web server, allowed unauthenticated remote access to a sensitive environment configuration file — exposing database and SMTP credentials.