<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:12:36.844145+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-367904</id>
    <title>EUVD-2026-367904</title>
    <updated>2026-10-02T15:12:36.911097+00:00</updated>
    <content>EUVD-2026-367904</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-367904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-50459</id>
    <title>fkie_cve-2023-50459</title>
    <updated>2026-10-02T15:12:36.911131+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-50459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4xp5-hr35-84cx</id>
    <title>GHSA-4xp5-hr35-84cx — Broken Access Control in extension "femanager"</title>
    <updated>2026-10-02T15:12:36.911164+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: in2code/femanager</p>
<p>The extension fails to check access permissions for the edit user component. An authenticated frontend user can use the vulnerability to either edit data of various frontend users or to delete various frontend user accounts.</p>
<p>Another missing access check in the backend module of the extensions allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser and resendUserConfirmation) for any frontend user in the system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4xp5-hr35-84cx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-50459</id>
    <title>gsd-2023-50459</title>
    <updated>2026-10-02T15:12:36.911191+00:00</updated>
    <content>gsd-2023-50459</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-50459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3144</id>
    <title>WID-SEC-W-2023-3144 — TYPO3 Extensions: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:12:36.911204+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in verschiedenen TYPO3 Extensions ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen und beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3144"/>
  </entry>
</feed>
