<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56825-shopper-collection-products-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:50:26.289Z</news:publication_date>
      <news:title>CVE-2026-56825: Shopper CollectionProducts Missing Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56828-shopper-framework-livewire-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:54:58.838Z</news:publication_date>
      <news:title>CVE-2026-56828: shopper/framework Privilege Escalation via Livewire Misconfigured Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56829-shopper-variantstock-missing-authorization-inventory-manipulation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:51:37.206Z</news:publication_date>
      <news:title>CVE-2026-56829: Shopper VariantStock Missing Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59148-mockoon-unauthenticated-admin-api-csrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T22:09:15.823Z</news:publication_date>
      <news:title>CVE-2026-59148: @mockoon/commons-server Unauthenticated Admin API + Wildcard CORS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59151-prowler-saml-cross-tenant-account-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:49:20.475Z</news:publication_date>
      <news:title>CVE-2026-59151: Prowler SAML Cross-Tenant Account Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59973-mcp-from-openapi-ssrf-filter-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T22:10:28.749Z</news:publication_date>
      <news:title>CVE-2026-59973: mcp-from-openapi OpenAPI $ref SSRF Filter Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61534-yayson-prototype-pollution-jsonapi-store</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T22:28:51.427Z</news:publication_date>
      <news:title>CVE-2026-61534: yayson Prototype Pollution via JSON:API Type Deserialization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>