<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:26:27.385707+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-drupal-2021-41183</id>
    <title>BIT-drupal-2021-41183 — XSS in `*Text` options of the Datepicker widget</title>
    <updated>2026-10-02T14:26:27.547018+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: drupal</p>
<p>jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-drupal-2021-41183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-058</id>
    <title>certfr-2022-avi-058 — De multiples vulnérabilités ont été découvertes dans Drupal core. Elles
permettent à un attaquant de provoquer une inje…</title>
    <updated>2026-10-02T14:26:27.547072+00:00</updated>
    <content>certfr-2022-avi-058</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-nd69835</id>
    <title>CLEANSTART-2024-ND69835 — jQuery-UI is the official jQuery user interface library</title>
    <updated>2026-10-02T14:26:27.547092+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: drupal7</p>
<p>Security vulnerability affects the drupal7 package. jQuery-UI is the official jQuery user interface library.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-nd69835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-215980</id>
    <title>EUVD-2026-215980</title>
    <updated>2026-10-02T14:26:27.547112+00:00</updated>
    <content>EUVD-2026-215980</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-215980"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-41183</id>
    <title>fkie_cve-2021-41183</title>
    <updated>2026-10-02T14:26:27.547124+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-41183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j7qv-pgf6-hvh4</id>
    <title>GHSA-j7qv-pgf6-hvh4 — XSS in `*Text` options of the Datepicker widget in jquery-ui</title>
    <updated>2026-10-02T14:26:27.547146+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: jquery-ui, Maven: org.webjars.npm:jquery-ui, RubyGems: jquery-ui-rails, NuGet: jQuery.UI.Combined</p>
<p>### Impact
Accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. For example, initializing the datepicker in the following way:
```js
$( "#datepicker" ).datepicker( {
	showButtonPanel: true,
	showOn: "both",
	closeText: "&lt;script&gt;doEvilThing( 'closeText XSS' )&lt;/script&gt;",
	currentText: "&lt;script&gt;doEvilThing( 'currentText XSS' )&lt;/script&gt;",
	prevText: "&lt;script&gt;doEvilThing( 'prevText XSS' )&lt;/script&gt;",
	nextText: "&lt;script&gt;doEvilThing( 'nextText XSS' )&lt;/script&gt;",
	buttonText: "&lt;script&gt;doEvilThing( 'buttonText XSS' )&lt;/script&gt;",
	appendText: "&lt;script&gt;doEvilThing( 'appendText XSS' )&lt;/script&gt;",
} );
```
will call `doEvilThing` with 6 different parameters coming from all `*Text` options.</p>
<p>### Patches
The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML.</p>
<p>### Workarounds
A workaround is to not accept the value of the `*Text` options from untrusted sources.</p>
<p>### For more information
If you have any questions or comments about this advisory, search for a relevant issue in [the jQuery UI repo](https://github.com/jquery/jquery-ui/issues). If you don't find an answer, open a new issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j7qv-pgf6-hvh4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-41183</id>
    <title>gsd-2021-41183</title>
    <updated>2026-10-02T14:26:27.547184+00:00</updated>
    <content>gsd-2021-41183</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-41183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1693</id>
    <title>OESA-2022-1693 — python-XStatic-jquery-ui security update</title>
    <updated>2026-10-02T14:26:27.547196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP3: python-XStatic-jquery-ui</p>
<p>jquery-ui javascript library packaged for setuptools (easy_install) / pip. This package is intended to be used by **any** project that needs these files. It intentionally does **not** provide any extra code except some metadata **nor** has any extra requirements. You MAY use some minimal support code from the XStatic base package, if you like. You can find more info about the xstatic packaging way in the package `XStatic`.

Security Fix(es):

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.(CVE-2021-41183)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1693"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:4711</id>
    <title>RHSA-2022:4711 — Red Hat Security Advisory: RHV Manager (ovirt-engine) [ovirt-4.5.0] security update</title>
    <updated>2026-10-02T14:26:27.547231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes nodejs-trim-off-newlines: ReDoS via string processing nodejs-normalize-url: ReDoS for data URLs jquery-ui: XSS in the altField option of the datepicker widget jquery-ui: XSS in *Text options of the datepicker widget jquery-ui: XSS in the 'of' option of the .position() util</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:4711"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41183</id>
    <title>UBUNTU-CVE-2021-41183</title>
    <updated>2026-10-02T14:26:27.547259+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: jqueryui, Ubuntu:Pro:16.04:LTS: jqueryui, Ubuntu:Pro:18.04:LTS: jqueryui, Ubuntu:20.04:LTS: jqueryui</p>
<p>jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-019</id>
    <title>VDE-2022-019 — Endress+Hauser: Multiple products utilizing vulnerable WIBU-SYSTEMS CodeMeter components</title>
    <updated>2026-10-02T14:26:27.547282+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-019"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1729</id>
    <title>WID-SEC-W-2022-1729 — jQuery: Mehrere Schwachstellen ermöglichen Cross-Site Scripting</title>
    <updated>2026-10-02T14:26:27.547300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in jQuery ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1729"/>
  </entry>
</feed>
