Posted by Karol Wrótniak on Jan 29
Summary
=======
A vulnerability was discovered in the popular JavaScript library
‘validator’.
The isLength() function incorrectly handles Unicode Variation Selectors
(U+FE0E and U+FE0F). An attacker can inject thousands of these zero-width
characters into a string, causing the library to report a much smaller
perceived length than the actual byte size. This leads to validation
bypasses,
potential database truncation, and Denial of…
– Read More – Full Disclosure
![[KIS-2026-03] Blesta <= 5.13.1 (2Checkout) Multiple PHP Object Injection Vulnerabilities AttackFeed by Joe Wagner | [KIS-2026-03] Blesta](https://attackfeed.com/wp-content/uploads/2026/02/fulldisclosure-img-taKmXU.webp)
![[KIS-2026-01] Blesta <= 5.13.1 (confirm_url) Reflected Cross-Site Scripting Vulnerability AttackFeed by Joe Wagner | [KIS-2026-01] Blesta](https://attackfeed.com/wp-content/uploads/2026/02/fulldisclosure-img-gNG0t6.webp)

