<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T19:27:18.652104+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232767</id>
    <title>EUVD-2026-232767</title>
    <updated>2026-10-07T19:27:18.655689+00:00</updated>
    <content>EUVD-2026-232767</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24833</id>
    <title>fkie_cve-2022-24833</title>
    <updated>2026-10-07T19:27:18.655725+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In PrivateBin &lt; v1.4.0 a cross-site scripting (XSS) vulnerability was found. The vulnerability is present in all versions from v0.21 of the project, which was at the time still called ZeroBin. The issue is caused by the fact that SVGs can contain JavaScript. This can allow an attacker to execute code, if the user opens a paste with a specifically crafted SVG attachment, and interacts with the preview image and the instance isn't protected by an appropriate content security policy. Users are advised to either upgrade to version 1.4.0 or to ensure the content security policy of their instance is set correctly.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-24833"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cqcc-mm6x-vmvw</id>
    <title>GHSA-cqcc-mm6x-vmvw — Persistent Cross-site Scripting vulnerability in PrivateBin</title>
    <updated>2026-10-07T19:27:18.655761+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: privatebin/privatebin</p>
<p>In PrivateBin &lt; v1.4.0 a cross-site scripting (XSS) vulnerability was found. The vulnerability is present since attachments with image preview got introduced in v0.21 of the project, which was at the time still called ZeroBin. The issue is caused by the fact that SVGs can contain JavaScript. This can allow an attacker to execute code, if the user opens a paste with a specifically crafted SVG attachment, and interacts with the preview image and the instance isn't protected by an appropriate content security policy.</p>
<p>As a consequence, we have mitigated the vulnerability in the preview and urge server administrators to either **upgrade** to a version with the fix or to ensure the content security policy of their instance is set correctly, ideally both. Additionally, we expanded our [directory listing tool with a checking mechanism](https://privatebin.info/directory/check) and **highly suggest server administrators to check their instance there** and, should there be a warning regarding the content security policy **adjust the CSP to our suggested one**, as it is shown in the configuration preset.</p>
<p>## Proof of concept</p>
<p>The vulnerability can be triggered as following:</p>
<p>1. Create the following SVG as a file:
```svg
&lt;?xml version="1.0" standalone="no"?&gt;
&lt;!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"&gt;</p>
<p>&lt;svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg"&gt;
 &lt;polygon id="triangle" points="0,0 0,50 50,0" fill="#0099…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cqcc-mm6x-vmvw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-24833</id>
    <title>gsd-2022-24833</title>
    <updated>2026-10-07T19:27:18.655855+00:00</updated>
    <content>gsd-2022-24833</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-24833"/>
  </entry>
</feed>
