<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Support Forum - Topic: xss</title>
		<link>http://www.kriesi.at/support/topic/xss</link>
		<description>Support Forum - Topic: xss</description>
		<language>en-US</language>
		<pubDate>Thu, 23 May 2013 19:04:58 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.2</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>http://www.kriesi.at/support/search.php</link>
		</textInput>
		<atom:link href="http://www.kriesi.at/support/rss/topic/xss" rel="self" type="application/rss+xml" />

		<item>
			<title>Kriesi on "xss"</title>
			<link>http://www.kriesi.at/support/topic/xss#post-81706</link>
			<pubDate>Wed, 31 Oct 2012 14:38:41 +0000</pubDate>
			<dc:creator>Kriesi</dc:creator>
			<guid isPermaLink="false">81706@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hey! We got multiple updates in the pipeline already that only wait for themeforest approval, during the next few days we will check each of the mentioned themes and upload the fix if necessary :)&#60;/p&#62;
&#60;p&#62;Flashlight update should be approved within the next few hours&#60;/p&#62;
&#60;p&#62;Best regards&#60;br /&#62;
Kriesi
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Dude on "xss"</title>
			<link>http://www.kriesi.at/support/topic/xss#post-81687</link>
			<pubDate>Wed, 31 Oct 2012 13:17:22 +0000</pubDate>
			<dc:creator>Dude</dc:creator>
			<guid isPermaLink="false">81687@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi! &#60;/p&#62;
&#60;p&#62; Kriesi updated Choices today (version 1.6) and this update already takes care of the XSS vulnerability. Other theme updates (eg for Flashlight) will be released today, this week or next week. &#60;/p&#62;
&#60;p&#62; Best regards,&#60;br /&#62;
Peter
&#60;/p&#62;</description>
		</item>
		<item>
			<title>luigioss on "xss"</title>
			<link>http://www.kriesi.at/support/topic/xss#post-81640</link>
			<pubDate>Wed, 31 Oct 2012 07:11:33 +0000</pubDate>
			<dc:creator>luigioss</dc:creator>
			<guid isPermaLink="false">81640@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;it's an important issue
&#60;/p&#62;</description>
		</item>
		<item>
			<title>luigioss on "xss"</title>
			<link>http://www.kriesi.at/support/topic/xss#post-81559</link>
			<pubDate>Tue, 30 Oct 2012 15:58:21 +0000</pubDate>
			<dc:creator>luigioss</dc:creator>
			<guid isPermaLink="false">81559@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;i got this message&#60;/p&#62;
&#60;p&#62;XSS vulnerability in Wordpress themes by Kriesi&#60;br /&#62;
According to my tests, the following premium Wordpress themes by Kriesi are affected by a reflected Cross-site Scripting (XSS) vulnerability:&#60;/p&#62;
&#60;p&#62;Abundance - 1,952 sales&#60;br /&#62;
Eunoia - 378 sales&#60;br /&#62;
Choices - 1,248 sales&#60;br /&#62;
Brightbox - 892 sales&#60;br /&#62;
Broadscope - 1,039 sales&#60;br /&#62;
Corona - 1,712 sales&#60;br /&#62;
Flashlight - 2,956 sales&#60;br /&#62;
Coalition - 1,079 sales&#60;br /&#62;
Shoutbox - 988 sales&#60;br /&#62;
Velvet - 600 sales&#60;br /&#62;
Upscale - 346 sales&#60;br /&#62;
Expose - 473 sales&#60;br /&#62;
Propulsion - 2,133 sales (added 30-Oct)&#60;br /&#62;
Sentence - 712 sales (added 30-Oct)&#60;br /&#62;
Sales figures are based on Themeforest statistics. Over 16,000 web sites could be affected. &#60;/p&#62;
&#60;p&#62;Developer status: notified initially on 5th of October&#60;br /&#62;
Latest developer response (24-Oct) : rolling out fixes in the near future.&#60;br /&#62;
Developer home page: &#60;a href=&#34;http://www.kriesi.at/&#34; rel=&#34;nofollow&#34;&#62;http://www.kriesi.at/&#60;/a&#62;&#60;br /&#62;
Official support forum: &#60;a href=&#34;http://www.kriesi.at/support/&#34; rel=&#34;nofollow&#34;&#62;http://www.kriesi.at/support/&#60;/a&#62; &#60;/p&#62;
&#60;p&#62;what about?
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
