<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T22:54:58.844930+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-196430</id>
    <title>EUVD-2026-196430</title>
    <updated>2026-10-05T22:54:58.848773+00:00</updated>
    <content>EUVD-2026-196430</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-196430"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-37259</id>
    <title>fkie_cve-2023-37259</title>
    <updated>2026-10-05T22:54:58.848805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. The Export Chat feature includes certain attacker-controlled elements in the generated document without sufficient escaping, leading to stored Cross site scripting (XSS). Since the Export Chat feature generates a separate document, an attacker can only inject code run from the `null` origin, restricting the impact. However, the attacker can still potentially use the XSS to leak message contents. A malicious homeserver is a potential attacker since the affected inputs are controllable server-side. This issue has been addressed in commit `22fcd34c60` which is included in release version 3.76.0. Users are advised to upgrade. The only known workaround for this issue is to disable or to not use the Export Chat feature.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-37259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c9vx-2g7w-rp65</id>
    <title>GHSA-c9vx-2g7w-rp65 — matrix-react-sdk vulnerable to XSS in Export Chat feature</title>
    <updated>2026-10-05T22:54:58.848838+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: matrix-react-sdk</p>
<p>### Description</p>
<p>The Export Chat feature includes certain attacker-controlled elements in the generated document without sufficient escaping, leading to stored XSS.</p>
<p>### Impact</p>
<p>Since the Export Chat feature generates a separate document, an attacker can only inject code run from the `null` origin, restricting the impact.</p>
<p>However, the attacker can still potentially use the XSS to leak message contents. A malicious homeserver is a potential attacker since the affected inputs are controllable server-side.</p>
<p>### Patches
This was patched in matrix-react-sdk 3.76.0.</p>
<p>### Workarounds
None, other than not using the Export Chat feature.</p>
<p>### References
N/A</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c9vx-2g7w-rp65"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-37259</id>
    <title>gsd-2023-37259</title>
    <updated>2026-10-05T22:54:58.848870+00:00</updated>
    <content>gsd-2023-37259</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-37259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13054-1</id>
    <title>openSUSE-SU-2024:13054-1 — element-desktop-1.11.36-1.1 on GA media</title>
    <updated>2026-10-05T22:54:58.848882+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>element-desktop-1.11.36-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13054-1"/>
  </entry>
</feed>
