<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://justappsec.com/</loc>
<changefreq>weekly</changefreq>
<priority>1</priority>
</url>
<url>
<loc>https://justappsec.com/cves</loc>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/guides</loc>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/scorecard</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/contact</loc>
<changefreq>yearly</changefreq>
<priority>0.5</priority>
</url>
<url>
<loc>https://justappsec.com/responsible-disclosure</loc>
<changefreq>yearly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://justappsec.com/threat-model</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/threat-model/schema</loc>
<changefreq>monthly</changefreq>
<priority>0.5</priority>
</url>
<url>
<loc>https://justappsec.com/news</loc>
<changefreq>hourly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://justappsec.com/news/feed</loc>
<changefreq>hourly</changefreq>
<priority>0.3</priority>
</url>
<url>
<loc>https://justappsec.com/research</loc>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/training</loc>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-budibase-command-palette-stored-xss</loc>
<lastmod>2026-04-03T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-budibase-webhook-bash-rce</loc>
<lastmod>2026-04-03T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-exchange-reporter-plus-stored-xss-permission-report</loc>
<lastmod>2026-04-03T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-fastmcp-oauthproxy-consent-confused-deputy</loc>
<lastmod>2026-04-03T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-mlflow-job-api-basic-auth-bypass</loc>
<lastmod>2026-04-03T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-pymetasploit3-newline-command-injection</loc>
<lastmod>2026-04-03T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-tornado-cookie-attribute-injection</loc>
<lastmod>2026-04-03T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-azure-databricks-critical-ssrf-eop</loc>
<lastmod>2026-04-02T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-fastmcp-openapi-ssrf-path-traversal</loc>
<lastmod>2026-04-02T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-groupoffice-insecure-deserialization-rce</loc>
<lastmod>2026-04-02T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-oneuptime-unauth-workflow-execution</loc>
<lastmod>2026-04-02T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-perfmatters-path-traversal-file-deletion</loc>
<lastmod>2026-04-03T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-poetry-wheel-path-traversal</loc>
<lastmod>2026-04-02T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-sharefile-szc-preauth-rce-chain</loc>
<lastmod>2026-04-02T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-wisp-multipart-size-limit-bypass</loc>
<lastmod>2026-04-02T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-auth0-php-cookie-forgery</loc>
<lastmod>2026-04-01T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-clerk-ssrf-secret-key-leak</loc>
<lastmod>2026-04-01T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-convoy-jwt-signature-bypass</loc>
<lastmod>2026-04-01T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-deerflow-host-bash-sandbox-escape</loc>
<lastmod>2026-04-01T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-filebrowser-signup-shell-execution</loc>
<lastmod>2026-04-01T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-joomla-webservice-access-control-flaw</loc>
<lastmod>2026-04-01T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-juju-dqlite-auth-bypass</loc>
<lastmod>2026-04-01T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-llamacpp-rpc-unauthenticated-rce</loc>
<lastmod>2026-04-01T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-metinfo-unauth-php-code-injection-rce</loc>
<lastmod>2026-04-01T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-mw-wp-form-unauth-file-move</loc>
<lastmod>2026-04-02T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-openexr-htj2k-decoder-oob-write</loc>
<lastmod>2026-04-01T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-payload-password-reset-impersonation</loc>
<lastmod>2026-04-01T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-rack-unbounded-multipart-upload-dos</loc>
<lastmod>2026-04-02T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-04-w3-total-cache-user-agent-token-leak</loc>
<lastmod>2026-04-01T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-langchain-core-load-prompt-path-traversal</loc>
<lastmod>2026-03-31T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-lodash-template-imports-code-injection</loc>
<lastmod>2026-03-31T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-mikroorm-critical-sql-injection</loc>
<lastmod>2026-03-31T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-openclaw-scp-command-injection</loc>
<lastmod>2026-03-31T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-siyuan-permissive-cors-electron-rce</loc>
<lastmod>2026-03-31T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-axios-npm-supply-chain-rat</loc>
<lastmod>2026-03-30T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-mlflow-model-artifact-command-injection</loc>
<lastmod>2026-03-30T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-nginx-ui-unauthenticated-mcp-takeover</loc>
<lastmod>2026-03-30T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-gitlab-jira-connect-install-credential-impersonation</loc>
<lastmod>2026-03-29T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-openclaw-device-token-rotate-scope-priv-esc</loc>
<lastmod>2026-03-29T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-trino-iceberg-rest-catalog-credential-leak</loc>
<lastmod>2026-03-29T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-perl-http-session-predictable-session-ids</loc>
<lastmod>2026-03-28T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-bludit-api-file-upload-rce</loc>
<lastmod>2026-03-27T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-dd-trace-java-rmi-deserialization-rce</loc>
<lastmod>2026-03-27T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-flannel-extension-backend-command-injection</loc>
<lastmod>2026-03-27T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-foreman-websocket-proxy-command-injection-rce</loc>
<lastmod>2026-03-27T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-handlebars-ast-injection-rce</loc>
<lastmod>2026-03-27T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-minio-sse-metadata-injection-object-bricking</loc>
<lastmod>2026-03-27T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-openbao-oidc-direct-callback-remote-phishing</loc>
<lastmod>2026-03-27T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-pyload-ssrf-cloud-metadata-exfiltration</loc>
<lastmod>2026-03-27T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-webkitgtk-wpe-webkit-multi-cve-web-content-bypass</loc>
<lastmod>2026-03-27T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-buildkit-malicious-frontend-file-escape</loc>
<lastmod>2026-03-26T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-etcd-grpc-authorization-bypass</loc>
<lastmod>2026-03-26T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-incus-template-sandbox-bypass</loc>
<lastmod>2026-03-27T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-saloon-unserialize-object-injection</loc>
<lastmod>2026-03-26T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-spring-ai-spel-injection-rce</loc>
<lastmod>2026-03-26T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-hitachi-ops-center-analyzer-xss</loc>
<lastmod>2026-03-25T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-n8n-prototype-pollution-rce</loc>
<lastmod>2026-03-25T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-opencart-search-sql-injection</loc>
<lastmod>2026-03-25T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-dagu-api-path-traversal-incomplete-fix</loc>
<lastmod>2026-03-24T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-langflow-actions-shell-injection</loc>
<lastmod>2026-03-24T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-minio-oidc-jwt-confusion</loc>
<lastmod>2026-03-24T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-mod-gnutls-client-cert-chain-overflow</loc>
<lastmod>2026-03-24T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-avideo-clonesite-unauth-rce-chain</loc>
<lastmod>2026-03-23T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-graphiti-arbitrary-method-execution</loc>
<lastmod>2026-03-23T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-jsrsasign-dsa-verification-bypass</loc>
<lastmod>2026-03-23T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-mantisbt-soap-auth-bypass-mysql</loc>
<lastmod>2026-03-23T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-mbconnect24-unauthenticated-rce</loc>
<lastmod>2026-03-23T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-tekton-git-resolver-path-traversal</loc>
<lastmod>2026-03-23T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-wp-dsgvo-unauth-account-destruction</loc>
<lastmod>2026-03-24T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-avideo-clonesite-arbitrary-file-deletion</loc>
<lastmod>2026-03-22T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-reviewx-unauth-limited-rce</loc>
<lastmod>2026-03-23T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-trivy-docker-images-compromised</loc>
<lastmod>2026-03-22T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-wp-maps-orderby-unauth-sqli</loc>
<lastmod>2026-03-22T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-idoit-cmdb-arbitrary-file-download</loc>
<lastmod>2026-03-21T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-libfuse-io-uring-memory-safety</loc>
<lastmod>2026-03-21T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-pyopenssl-dtls-cookie-callback-overflow</loc>
<lastmod>2026-03-20T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-trivy-github-actions-supply-chain-compromise</loc>
<lastmod>2026-03-20T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-deno-child-process-shell-command-injection</loc>
<lastmod>2026-03-13T00:01:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-sandboxjs-sandbox-escape</loc>
<lastmod>2026-03-13T00:01:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-curl-bearer-token-leak-redirect-netrc</loc>
<lastmod>2026-03-11T08:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-oneuptime-synthetic-monitor-probe-rce</loc>
<lastmod>2026-03-10T00:01:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-budibase-webhook-query-auth-bypass</loc>
<lastmod>2026-03-09T20:55:52.765Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-budibase-postgres-command-injection</loc>
<lastmod>2026-03-09T00:01:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-go-1261-1258-five-cve-fixes</loc>
<lastmod>2026-03-06T01:52:15.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-copilot-cli-shell-expansion-rce</loc>
<lastmod>2026-03-06T00:01:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-pingora-http-request-smuggling</loc>
<lastmod>2026-03-04T23:32:41.186Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-pac4j-jwt-auth-bypass</loc>
<lastmod>2026-03-04T22:18:27.284Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-artemis-core-federation-auth-bypass</loc>
<lastmod>2026-03-04T00:01:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-zammad-critical-sql-injection-zaa-2026-06</loc>
<lastmod>2026-03-04T00:01:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-qwik-unauthenticated-rce</loc>
<lastmod>2026-03-03T22:55:38.064Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-openstack-vitrage-query-parser-rce</loc>
<lastmod>2026-03-03T17:44:02.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-03-github-actions-weak-config-active-exploitation</loc>
<lastmod>2026-03-03T03:57:18.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-fastify-middie-path-normalization-auth-bypass</loc>
<lastmod>2026-02-28T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-ocaml-marshal-deserialization-rce</loc>
<lastmod>2026-02-27T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-hoppscotch-unauth-onboarding-config-takeover</loc>
<lastmod>2026-02-26T22:34:46.524Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-openlit-github-actions-pull-request-target</loc>
<lastmod>2026-02-26T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-terraform-linode-provider-debug-log-leak</loc>
<lastmod>2026-02-26T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-n8n-expression-sandbox-rce</loc>
<lastmod>2026-02-25T22:19:44.806Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-cline-cli-npm-token-compromise</loc>
<lastmod>2026-02-25T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-imagemagick-policy-bypass-path-traversal</loc>
<lastmod>2026-02-24T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-superset-dataset-authorization-bypass</loc>
<lastmod>2026-02-24T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-vmware-aria-operations-vmsa-2026-0001</loc>
<lastmod>2026-02-24T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-claude-code-security-preview</loc>
<lastmod>2026-02-21T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-sentry-saml-sso-takeover</loc>
<lastmod>2026-02-21T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-node-tar-hardlink-escape</loc>
<lastmod>2026-02-20T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-strimzi-mtls-ca-chain-trust</loc>
<lastmod>2026-02-20T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-jenkins-core-stored-xss-offline-cause</loc>
<lastmod>2026-02-18T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-red-hat-nodejs20-security-update</loc>
<lastmod>2026-02-17T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-malicious-npm-ambar-src</loc>
<lastmod>2026-02-16T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/news/2026-02-npm-compass-e2e-tests-malicious</loc>
<lastmod>2026-02-16T00:00:00.000Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://justappsec.com/research/authentication</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/business-logic-abuse</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/command-injection</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/cross-origin-resource-sharing</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/cross-site-request-forgery</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/cross-site-scripting</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/file-upload-security</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/insecure-direct-object-references</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/json-web-tokens</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/mass-assignment</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/password-storage</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/path-traversal</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/prompt-injection</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/prototype-pollution</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/row-level-security-patterns-for-postgres</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/secure-software-development-lifecycle</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/server-side-request-forgery</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/session-management</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/sql-injection</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/template-injection</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/research/threat-modeling</loc>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/communicating-appsec-risk-to-leadership</loc>
<lastmod>2026-03-23T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/cyber-essentials-for-development-teams</loc>
<lastmod>2026-03-23T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/supply-chain-security-fundamentals</loc>
<lastmod>2026-03-23T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/api-key-security-best-practices</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/how-to-secure-nextjs</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/jwt-security-best-practices</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/llm-tool-calling-security</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/mtls-vs-jwt-vs-oauth-for-service-auth</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/nextjs-csp-configuration</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/nextjs-security-checklist</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/nextjs-ssrf-protection</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/oauth-2-security-best-practices</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/prompt-injection-prevention</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/rate-limiting-in-nodejs</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/secrets-management-in-github-actions</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/secure-file-uploads-in-nodejs</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/secure-password-storage-bcrypt-vs-argon2</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/secure-session-management</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/secure-webhook-verification</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/securing-rag-pipelines</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/service-to-service-authentication-best-practices</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/sql-injection-prevention-with-prisma</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/guides/webhook-replay-attack-protection</loc>
<lastmod>2026-03-04T00:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://justappsec.com/training/thinking-like-an-attacker</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/code-review-for-security</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/web-application-testing</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/api-security-testing</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/bug-bounty-and-responsible-disclosure</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/red-team-basics-for-builders</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/secure-defaults-in-modern-frameworks</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/api-design-that-defends-itself</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/data-protection-and-encryption</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/secrets-management</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/microservice-and-serverless-boundaries</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/ai-integration-security</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/injection-today</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/xss-in-modern-frameworks</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/authentication-patterns</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/authorisation-and-access-control</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/session-management</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/secure-file-handling</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/input-validation-and-schema-enforcement</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/ssrf-and-request-forgery</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/logging-and-detection-engineering</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/monitoring-and-alerting-for-security-events</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/incident-response-for-teams-that-ship-daily</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/vulnerability-management</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/waf-cdn-and-edge-security</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/compliance-as-code</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/cicd-pipeline-security</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/dependency-and-supply-chain-management</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/container-and-image-security</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/infrastructure-as-code</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/secrets-in-pipelines</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/artifact-signing-and-provenance</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/security-mindset-for-developers</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/threat-modelling-without-the-ceremony</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/attack-surface-of-a-modern-web-app</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/trust-boundaries-and-data-flow</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/bridging-dev-and-security-teams</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://justappsec.com/training/labs/xss-encoding</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
</urlset>
