<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T16:04:42.341631+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-209811</id>
    <title>EUVD-2026-209811</title>
    <updated>2026-10-04T16:04:42.476720+00:00</updated>
    <content>EUVD-2026-209811</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-209811"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-23913</id>
    <title>fkie_cve-2023-23913</title>
    <updated>2026-10-04T16:04:42.476755+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-23913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xp5h-f8jf-rc8q</id>
    <title>GHSA-xp5h-f8jf-rc8q — rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements</title>
    <updated>2026-10-04T16:04:42.476789+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionview</p>
<p>NOTE: rails-ujs is part of Rails/actionview since 5.1.0.</p>
<p>There is a potential DOM based cross-site scripting issue in rails-ujs
which leverages the Clipboard API to target HTML elements that are
assigned the contenteditable attribute. This has the potential to
occur when pasting malicious HTML content from the clipboard that
includes a data-method, data-remote or data-disable-with attribute.</p>
<p>This vulnerability has been assigned the CVE identifier CVE-2023-23913.</p>
<p>Not affected: &lt; 5.1.0
Versions Affected: &gt;= 5.1.0
Fixed Versions: 6.1.7.3, 7.0.4.3</p>
<p>Impact
  If the specified malicious HTML clipboard content is provided to a
  contenteditable element, this could result in the arbitrary execution
  of javascript on the origin in question.</p>
<p>Releases
  The FIXED releases are available at the normal locations.</p>
<p>Workarounds
  We recommend that all users upgrade to one of the FIXED versions.
  In the meantime, users can attempt to mitigate this vulnerability
  by removing the contenteditable attribute from elements in pages
  that rails-ujs will interact with.</p>
<p>Patches
  To aid users who aren’t able to upgrade immediately we have provided
  patches for the two supported release series. They are in git-am
  format and consist of a single changeset.</p>
<p>* rails-ujs-data-method-contenteditable-6-1.patch - Patch for 6.1 series
* rails-ujs-data-method-contenteditable-7-0.patch - Patch for 7.0 series</p>
<p>Please note that only the 7.0.Z and 6.1.Z series are
supported at present, and 6.0.Z for sev…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xp5h-f8jf-rc8q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-23913</id>
    <title>gsd-2023-23913</title>
    <updated>2026-10-04T16:04:42.476842+00:00</updated>
    <content>gsd-2023-23913</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-23913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1774</id>
    <title>OESA-2024-1774 — rubygem-actionview security update</title>
    <updated>2026-10-04T16:04:42.476856+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: rubygem-actionview</p>
<p>Simple, battle-tested conventions and helpers for building web pages.

Security Fix(es):

A flaw was found in Rails. rails-ujs may allow an attacker to perform Cross-Site Scripting (XSS), which could lead to stolen information, phishing attacks, and other types of attacks.(CVE-2023-23913)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1774"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:3813-1</id>
    <title>SUSE-SU-2023:3813-1 — Security update for rubygem-actionview-5_1</title>
    <updated>2026-10-04T16:04:42.476876+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-actionview-5_1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:3813-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-23913</id>
    <title>UBUNTU-CVE-2023-23913</title>
    <updated>2026-10-04T16:04:42.476893+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails</p>
<p>There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-23913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0632</id>
    <title>WID-SEC-W-2023-0632 — Ruby on Rails: Mehrere Schwachstellen</title>
    <updated>2026-10-04T16:04:42.476921+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, unbekannte Auswirkungen zu verursachen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0632"/>
  </entry>
</feed>
