{"id":52909,"date":"2023-07-24T13:24:09","date_gmt":"2023-07-24T13:24:09","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/34824\/WebBoss.io-CMS-Concerns-A-Tale-Of-Neglect-And-Unresponsiveness.html"},"modified":"2023-07-24T13:24:09","modified_gmt":"2023-07-24T13:24:09","slug":"webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/","title":{"rendered":"WebBoss.io CMS Concerns: A Tale Of Neglect And Unresponsiveness"},"content":{"rendered":"<p>In the world of cybersecurity, the safeguarding of sensitive data and the protection of users\u2019 privacy are of paramount importance. Companies that offer Software as a Service (SaaS) are entrusted with the responsibility of maintaining robust security practices to prevent unauthorized access and potential breaches. Unfortunately, one such SaaS provider, WebBoss.io, has fallen short of these expectations. The company\u2019s repeated lack of transparency regarding disclosed vulnerabilities raises serious concerns about their commitment to user safety and the protection of sensitive data.<\/p>\n<p>As an independent researcher, I recently foundmyself revisitng a vendor one year on. To my surprise, there was more to find, more to disclose, highlighting serious flaws that could jeopardize user data and the overall integrity of the system. The vulnerabilities reported included Reflected XSS, Insecure Direct Object Reference (IDOR), and other critical issues. However, instead of promptly addressing these concerns, WebBoss.io\u2019s response was lackluster and ineffective, raising significant questions about their commitment to cybersecurity.<\/p>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Critical_Vulnerabilities_Left_Unresolved\"><\/span>Critical Vulnerabilities Left Unresolved<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Among the vulnerabilities disclosed, the most alarming was the Critical Insecure Direct Object Reference (IDOR) vulnerability (<a rel=\"noreferrer noopener\" href=\"https:\/\/www.realinfosec.net\/advisories\/WEBBOSS-CMS-IDOR-2023-0xv3jsv.html\" target=\"_blank\" data-wpel-link=\"internal\">CVE-2023\u201336339<\/a>), which took the SaaS provider 59 days to address. Despite the severity of this issue, WebBoss.io failed to provide a specific date for the patch, and no mitigation measures were ever taken to protect users until the remediation process was complete, 59 days later. This flaw allows attackers to access the Website Backup Tool via a crafted GET request, leading to unauthorized access and data breaches.<\/p>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Further_Context\"><\/span>Further Context<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Rewind back to 2022, I responsibly disclosed security vulnerabilities to WebBoss.io, as part of my commitment to improving cybersecurity across the digital landscape. These disclosures included issues, such as Reflected XSS (<a rel=\"noreferrer noopener\" href=\"https:\/\/realinfosec.net\/advisories\/WEBBOSS-XSS-2022-0xd3fcf.html\" target=\"_blank\" data-wpel-link=\"internal\">CVE-2023\u201337742<\/a>), that could potentially allow attackers to execute malicious code on users\u2019 browsers. While WebBoss.io reportedly applied a \u201cSecurity Hotfix\u201d to address the vulnerabilities, they failed to inform their customers about the specific issues, hindering users\u2019 understanding of the urgency and importance of updating their systems, and most importantly they<strong> did not apply an adequate patch <\/strong>as vulnerable vectors (including the exact same one) were eveidently still present one year on. This worrisome sign, and the fact that a plethora of security issues were again identified suggests that WebBoss.io fails to perform its own security testing\u200a\/assessments\u2014\u200aeither by 3rd party or otherwise, which is a crucial and essential practice for any reputable and compliant organization, particularly in today\u2019s digital era where cyber threats and attacks are progressively more sophisticated and widespread.<\/p>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Negligent_Response_and_Transparency_Lacking\"><\/span>Negligent Response and Transparency Lacking<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>In 2023, throughout the entire disclosure process, WebBoss.io exhibited a negligent response to the reported vulnerabilities. Their communication was often dismissive and failed to provide concrete timelines for fixes. The lack of transparency was evident when the company claimed to have notified all customers about the patches, but I did not receive such notification, despite being signed up to their platforn, only after I raised this with them in a ticket did the email arrive.. many hours later.. Additionally, the inital changelog released by WebBoss.io failed to mention the CVE IDs for the recently disclosed vulnerabilities, hindering transparency and accountability.<\/p>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Important_Of_Transparency\"><\/span>Important Of Transparency<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Transparent communication is not merely a courtesy; it is a crucial aspect of security responsibility. When companies withhold critical information about vulnerabilities and security updates, they leave their users at risk. Without clear information, users may not recognize the severity of the situation or the urgency of applying patches. This lack of transparency undermines the trust users place in the company\u2019s commitment to their security.<\/p>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Disregard_for_Industry_Best_Practices\"><\/span>Disregard for Industry Best Practices<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>During my correspondence with WebBoss.io I highlighted several best practices and industry standards that WebBoss.io had evidently been disregarded, including vulnerability management, incident response and monitoring, customer notification, security assessments, and data privacy and protection. Neglecting these essential security measures raises serious concerns about WebBoss.io\u2019s commitment to safeguarding their customers\u2019 data and complying with relevant data protection regulations.<\/p>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"A_Terrible_Attempt_Of_Silencing_The_Situation\"><\/span>A Terrible Attempt Of Silencing The Situation<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>WebBoss.io malicously accused me of blackmail and involved the police, but the authorities swiftly dismissed the claim. I want to clarify that I never had any ulterior motive, nor did I make any demands. I simply told them if a patch was not released within 28 days, I would proceed with public disclosure.<\/p>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Protecting_User_Data_Should_be_Paramount\"><\/span>Protecting User Data Should be Paramount<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>As a SaaS provider, WebBoss.io holds sensitive user data, which should makes security a top priority. However, their repeated lack of transparency raises questions about their dedication to protecting user data. Adequate disclosure of security vulnerabilities empowers users to take appropriate action, ensures they are aware of potential risks, and fosters a sense of trust between users and the company.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><picture><source sizes=\"(max-width: 574px) 100vw, 574px\" type=\"image\/webp\" srcset=\"https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image.png.webp 574w, https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image-300x121.png.webp 300w, https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image-150x60.png.webp 150w\"><img loading=\"lazy\" decoding=\"async\" width=\"574\" height=\"231\" src=\"https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image.png\" alt=\"webboss ISO 27001\" class=\"wp-image-29384 lazyload\" data-eio=\"p\" data-sizes=\"auto\" data-eio-rwidth=\"574\" data-eio-rheight=\"231\" srcset=\"https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image.png 574w, https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image-300x121.png 300w, https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image-150x60.png 150w\"><noscript><img loading=\"lazy\" decoding=\"async\" width=\"574\" height=\"231\" src=\"https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image.png\" alt=\"webboss ISO 27001\" class=\"wp-image-29384\" srcset=\"https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image.png 574w, https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image-300x121.png 300w, https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image-150x60.png 150w\" sizes=\"auto, (max-width: 574px) 100vw, 574px\" data-eio=\"l\"><\/noscript><\/picture><\/figure>\n<\/div>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Final_Thoughts\"><\/span>Final Thoughts<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The handling of security disclosures by WebBoss.io has been riddled with negligence, unresponsiveness, and a lack of transparency. The delayed response to critical vulnerabilities and the failure to prioritize user data protection reveal a disconcerting lack of commitment to cybersecurity best practices.<\/p>\n<p>As a responsible security researcher, I made every effort to highlight these vulnerabilities and prompt WebBoss.io to take appropriate action as swiftly as possible. Regrettably, the company\u2019s response and handling has been inadequate, prompting me to seek public disclosure. This unfortunate situation could have been avoided had WebBoss.io demonstrated a more proactive approach to security, conducted their own due-dillegence and promptly addressed the reported vulnerabilities, or at they very least provide dates for patches.<\/p>\n<p>As users of WebBoss.io\u2019s SaaS services, it is essential to be vigilant and take precautionary measures to protect sensitive data when using this sytem. Customers should urge the company to prioritize security measures and demand transparency regarding the implementation of patches and future security enhancements.<\/p>\n<p>Depending on your use-case for WebBoss.io\u2019s CMS, It may be suggested to replace the affected object with an alternative, robust and transparent product.<\/p>\n<p>As earilier stipulated, and well recognized, In the world of cyber, the protection of user data should be paramount. Sadly, WebBoss.io\u2019s handling of security disclosures raises significant doubts about their commitment to ensuring the safety and privacy of their users.<\/p>\n<p><strong><em>I reached out to webboss for comment, allowing them the opportunity to have their say, but have yet to recevive any response.<\/em><\/strong><\/p>\n<p><a href=\"https:\/\/www.realinfosec.net\/support\/index.php?a=add&amp;category=3\" data-wpel-link=\"internal\" rel=\"noopener noreferrer\">Suggest an edit to this article<\/a><\/p>\n<p>Check out our new <a href=\"https:\/\/www.realinfosec.net\/discord\" target=\"_blank\" rel=\"noreferrer noopener\" data-wpel-link=\"internal\">Discord Cyber Awareness Server<\/a>. Stay informed with CVE Alerts, Cybersecurity News &amp; More!<\/p>\n<p><a href=\"https:\/\/www.realinfosec.net\/support\/knowledgebase.php\" data-wpel-link=\"internal\" rel=\"noopener noreferrer\">Cybersecurity Knowledge Base<\/a><\/p>\n<p><a href=\"https:\/\/www.realinfosec.net\/\" data-wpel-link=\"internal\" rel=\"noopener noreferrer\">Homepage<\/a><\/p>\n<p><strong><em>Remember,&nbsp;<\/em><\/strong><em>CyberSecurity Starts With You!<\/em><\/p>\n<ul>\n<li>Globally,&nbsp;<strong>30,000 websites<\/strong>&nbsp;are hacked daily.<\/li>\n<li><strong>64% of companies<\/strong>&nbsp;worldwide have experienced at least one form of a cyber attack.<\/li>\n<li>There were&nbsp;<strong>20M breached records<\/strong>&nbsp;in March 2021.<\/li>\n<li>In 2020, ransomware cases grew by&nbsp;<strong>150%<\/strong>.<\/li>\n<li>Email is responsible for around&nbsp;<strong>94% of all malware<\/strong>.<\/li>\n<li><strong>Every 39 seconds,<\/strong>&nbsp;there is a new attack somewhere on the web.<\/li>\n<li>An average of&nbsp;<strong>around 24,000 malicious mobile apps<\/strong>&nbsp;are blocked daily on the internet.<\/li>\n<\/ul>\n<div data-object_id=\"29345\" class=\"cbxwpbkmarkwrap cbxwpbkmarkwrap_guest cbxwpbkmarkwrap_user_cat cbxwpbkmarkwrap-post \"><a data-redirect-url=\"https:\/\/www.realinfosec.net\/infosec-news\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/\" data-display-label=\"1\" data-show-count=\"0\" data-bookmark-label=\"Bookmark\" data-bookmarked-label=\"Bookmarked\" data-loggedin=\"0\" data-type=\"post\" data-object_id=\"29345\" class=\"cbxwpbkmarktrig cbxwpbkmarktrig-button-addto\" title=\"Bookmark This\" href=\"https:\/\/www.realinfosec.net\/infosec-news\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/#\"><span class=\"cbxwpbkmarktrig-label\">Bookmark<\/span><\/a> <\/p>\n<div data-type=\"post\" data-object_id=\"29345\" class=\"cbxwpbkmarkguestwrap\" id=\"cbxwpbkmarkguestwrap-29345\">\n<div class=\"cbxwpbkmarkguest-message\" readability=\"6\">\n<h3 class=\"cbxwpbookmark-title cbxwpbookmark-title-login\"><span class=\"ez-toc-section\" id=\"Please_login_to_bookmark\"><\/span>Please login to bookmark<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"heateor_sss_sharing_container heateor_sss_horizontal_sharing\" data-heateor-sss-href=\"https:\/\/www.realinfosec.net\/infosec-news\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/\" readability=\"8\">\n<p>Share the word, let&#8217;s increase Cybersecurity Awareness as we know it<\/p>\n<\/div>\n<div class=\"td-a-ad id_bottom_ad \"><span class=\"td-adspot-title\">&#8211; Advertisement &#8211;<\/span><a href=\"https:\/\/www.tkqlhce.com\/click-100575598-15154696\" target=\"_blank\" data-wpel-link=\"external\" rel=\"follow external noopener\"><br \/>\n<img loading=\"lazy\" src=\"https:\/\/www.tqlkg.com\/image-100575598-15154696\" width=\"1960\" height=\"240\" alt border=\"0\" decoding=\"async\" class=\"lazyload\" data-eio-rwidth=\"1960\" data-eio-rheight=\"240\"><noscript><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.tqlkg.com\/image-100575598-15154696\" width=\"1960\" height=\"240\" alt border=\"0\" data-eio=\"l\"><\/noscript><\/a><\/div>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/34824\/WebBoss.io-CMS-Concerns-A-Tale-Of-Neglect-And-Unresponsiveness.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":52910,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[968],"class_list":["post-52909","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlineflaw"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>WebBoss.io CMS Concerns: A Tale Of Neglect And Unresponsiveness 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WebBoss.io CMS Concerns: A Tale Of Neglect And Unresponsiveness 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-24T13:24:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image.png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"WebBoss.io CMS Concerns: A Tale Of Neglect And Unresponsiveness\",\"datePublished\":\"2023-07-24T13:24:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\\\/\"},\"wordCount\":1179,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness.png\",\"keywords\":[\"headline,flaw\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\\\/\",\"name\":\"WebBoss.io CMS Concerns: A Tale Of Neglect And Unresponsiveness 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness.png\",\"datePublished\":\"2023-07-24T13:24:09+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness.png\",\"width\":574,\"height\":231},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,flaw\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlineflaw\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"WebBoss.io CMS Concerns: A Tale Of Neglect And Unresponsiveness\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"WebBoss.io CMS Concerns: A Tale Of Neglect And Unresponsiveness 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/","og_locale":"en_US","og_type":"article","og_title":"WebBoss.io CMS Concerns: A Tale Of Neglect And Unresponsiveness 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-07-24T13:24:09+00:00","og_image":[{"url":"https:\/\/www.realinfosec.net\/wp-content\/uploads\/2023\/07\/image.png","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"WebBoss.io CMS Concerns: A Tale Of Neglect And Unresponsiveness","datePublished":"2023-07-24T13:24:09+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/"},"wordCount":1179,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/07\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness.png","keywords":["headline,flaw"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/","url":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/","name":"WebBoss.io CMS Concerns: A Tale Of Neglect And Unresponsiveness 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/07\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness.png","datePublished":"2023-07-24T13:24:09+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/07\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/07\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness.png","width":574,"height":231},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/webboss-io-cms-concerns-a-tale-of-neglect-and-unresponsiveness\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,flaw","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlineflaw\/"},{"@type":"ListItem","position":3,"name":"WebBoss.io CMS Concerns: A Tale Of Neglect And Unresponsiveness"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52909","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=52909"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52909\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/52910"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=52909"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=52909"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=52909"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}