<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-52887-nocobase-in-app-message-sqli-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:48:55.944Z</news:publication_date>
      <news:title>CVE-2026-52887: NocoBase plugin-notification-in-app-message SQL Injection to RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53501-thumbor-hmac-signature-bypass-replace</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:30:06.179Z</news:publication_date>
      <news:title>CVE-2026-53501: thumbor HMAC Signature Validation Bypass via Repeated URL Segments</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53502-thumbor-file-loader-path-traversal-unquote-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:08:37.984Z</news:publication_date>
      <news:title>CVE-2026-53502: thumbor Path Traversal via Post-Validation URL Decode in file_loader</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53503-thumbor-convolution-divide-by-zero-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:12:10.260Z</news:publication_date>
      <news:title>CVE-2026-53503: thumbor convolution filter remote divide-by-zero DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53504-thumbor-redos-convolution-filter</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:11:02.892Z</news:publication_date>
      <news:title>CVE-2026-53504: thumbor ReDoS in convolution Filter</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53505-thumbor-proportion-filter-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:09:48.256Z</news:publication_date>
      <news:title>CVE-2026-53505: thumbor proportion filter Remote Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53599-redaxo-mediapool-double-extension-bypass-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:50:17.949Z</news:publication_date>
      <news:title>CVE-2026-53599: REDAXO Mediapool Multi-Segment Filename Extension Bypass RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53608-apostrophecms-seo-stored-xss-google-analytics-id</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T22:08:50.307Z</news:publication_date>
      <news:title>CVE-2026-53608: @apostrophecms/seo Stored XSS via Unsanitized Google Analytics ID</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53609-apostrophecms-prototype-pollution-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T22:09:57.142Z</news:publication_date>
      <news:title>CVE-2026-53609: ApostropheCMS Server-Side Prototype Pollution via $pullAll Leading to Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54910-filebrowser-quantum-subtitle-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T22:48:47.661Z</news:publication_date>
      <news:title>CVE-2026-54910: FileBrowser Quantum Path Traversal in Subtitle Handler</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58263-jodit-mathml-mutation-xss-clean-html-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-31T19:28:59.566Z</news:publication_date>
      <news:title>CVE-2026-58263: Jodit Editor Mutation XSS via MathML/style Rawtext Carrier</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>