Zero Spam
BitFire's FREE WAF and Bot Protection stop the unauthenticated Contact Form 7 POST that plants stored XSS in Zero Spam's admin Detection Log.
- Affected sites
- 20,000+
- Attack class
- Stored Cross-site Scripting
Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.
Showing 1–6 of 30 records · Updated September 25, 2026
BitFire's FREE WAF and Bot Protection stop the unauthenticated Contact Form 7 POST that plants stored XSS in Zero Spam's admin Detection Log.
BitFire's WAF blocks the wpForo CVE-2026-93747 stored XSS payload at the request layer, before it is stored or ever rendered to an admin.
BitFire FREE blocks the double-encoded traversal before vulnerable WordPress template resolution can include an attacker-selected PHP file.
BitFire FREE blocks the double-encoded traversal local file inclusion before vulnerable WordPress template resolution can include an attacker-selected PHP file.
BitFire FREE detects the serialized PHP object behind CVE-2026-82222 before GiveWP can deserialize it and trigger remote code execution.
BitFire blocks malicious uploads and PRO RASP prevents unauthorized PHAR creation through the vulnerable Contact Form 7 add-on.
Page 1 of 5
BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.