<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T13:33:46.554130+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232511</id>
    <title>EUVD-2026-232511</title>
    <updated>2026-10-07T13:33:46.556729+00:00</updated>
    <content>EUVD-2026-232511</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41928</id>
    <title>fkie_cve-2022-41928</title>
    <updated>2026-10-07T13:33:46.556767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` macro properties. This has been patched in versions 13.10.7, 14.4.2, and 14.5. The issue can be fixed on a running wiki by updating `XWiki.AttachmentSelector` with the versions below: - 14.5-rc-1+: https://github.com/xwiki/xwiki-platform/commit/eb15147adf94bddb92626f862c1710d45bcd64a7#diff-e1513599ab698991f6cbba55d38f3f464432ced8d137a668b1f7618c7e747e23 - 14.4.2+: https://github.com/xwiki/xwiki-platform/commit/c02f8eb1f3c953d124f2c097021536f8bc00fa8d#diff-e1513599ab698991f6cbba55d38f3f464432ced8d137a668b1f7618c7e747e23 - 13.10.7+: https://github.com/xwiki/xwiki-platform/commit/efd0df0468d46149ba68b66660b93f31b6318515#diff-e1513599ab698991f6cbba55d38f3f464432ced8d137a668b1f7618c7e747e23</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-41928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9hqh-fmhg-vq2j</id>
    <title>GHSA-9hqh-fmhg-vq2j — Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml</title>
    <updated>2026-10-07T13:33:46.556828+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.xwiki.platform:xwiki-platform-attachment-ui</p>
<p>### Impact
Any user with the right to edit his personal page can follow one of the scenario below:</p>
<p>**Scenario 1**:
- Log in as a simple user with just edit rights on the user profile
- Go to the user's profile
- Upload an attachment in the attachment tab at the bottom of the page (any image is fine)
- Click on "rename" in the attachment list and enter `{{async async="true" cached="false" context="doc.reference"}}{{groovy}}println("Hello from groovy!"){{/groovy}}{{/async}}.png` as new attachment name and submit the rename
- Go back to the user profile
- Click on the edit icon on the user avatar
- `Hello from groovy!` is displayed as the title of the attachment</p>
<p>**Scenario 2**:
- Log in as a simple user with just edit rights on a page
- Create a Page `MyPage.WebHome`
- Create an XClass field of type String named `avatar`
- Add an XObject of type `MyPage.WebHome` on the page
- Insert an `attachmentSelector` macro in the document with the following values:
  - **classname**: `MyPage.WebHome`
  - **property**: `avatar`
  - **savemode**: `direct`
  - **displayImage**: `true`
  - **width**: `]] {{async async="true" cached="false" context="doc.reference"}}{{groovy}}println("Hello from groovy!"){{/groovy}}{{/async}}`. You'll find below a snippet of an `attachmentSelector` macro declaration.
- Display the page
- Use the attachment picker to select an image
- `Hello from groovy` is displayed aside the image</p>
<p>Example of an `attachmentSelector` macro declaration:
```
`{{attachmentSelect…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9hqh-fmhg-vq2j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-41928</id>
    <title>gsd-2022-41928</title>
    <updated>2026-10-07T13:33:46.556891+00:00</updated>
    <content>gsd-2022-41928</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-41928"/>
  </entry>
</feed>
