<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T18:33:37.141680+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-14927</id>
    <title>bdu:2025-14927</title>
    <updated>2026-10-05T18:33:37.215689+00:00</updated>
    <content>bdu:2025-14927</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-14927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261950</id>
    <title>EUVD-2026-261950</title>
    <updated>2026-10-05T18:33:37.215749+00:00</updated>
    <content>EUVD-2026-261950</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261950"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21621</id>
    <title>fkie_cve-2025-21621</title>
    <updated>2026-10-05T18:33:37.215765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a reflected cross-site scripting (XSS) vulnerability exists in the WMS GetFeatureInfo HTML output format that enables a remote attacker to execute arbitrary JavaScript code in a victim's browser through specially crafted SLD_BODY parameters. This issue has been patched in version 2.25.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-21621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w66h-j855-qr72</id>
    <title>GHSA-w66h-j855-qr72 — GeoServer has a Reflected Cross-Site Scripting (XSS) vulnerability in its WMS GetFeatureInfo HTML format</title>
    <updated>2026-10-05T18:33:37.215801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.geoserver.web:gs-web-app, Maven: org.geoserver:gs-wms</p>
<p>### Summary
A reflected cross-site scripting (XSS) vulnerability exists in the WMS GetFeatureInfo HTML output format that enables a remote attacker to execute arbitrary JavaScript code in a victim's browser through specially crafted SLD_BODY parameters.</p>
<p>### Details</p>
<p>The WMS service setting that controls HTML auto-escaping is either disabled by default, or completely missing, in the affected versions (see workarounds).</p>
<p>### Impact</p>
<p>If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can:
1. Perform any action within the application that the user can perform.
2. View any information that the user is able to view.
3. Modify any information that the user is able to modify.
4. Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.</p>
<p>### Workarounds
Changing any of the following WMS service settings should mitigate this vulnerability in most environments:
1. Enable GetFeatureInfo HTML auto-escaping (available in GeoServer 2.21.3+ and 2.22.1+)
2. Disable dynamic styling
3. Disable GetFeatureInfo text/html MIME type</p>
<p>### References
https://osgeo-org.atlassian.net/browse/GEOS-11297
https://github.com/geoserver/geoserver/pull/7406</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w66h-j855-qr72"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2676</id>
    <title>WID-SEC-W-2025-2676 — GeoServer: Mehrere Schwachstellen</title>
    <updated>2026-10-05T18:33:37.215843+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in GeoServer ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um Informationen offenzulegen, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2676"/>
  </entry>
</feed>
