<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:57:54.178776+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-268152</id>
    <title>EUVD-2026-268152</title>
    <updated>2026-10-02T11:57:54.181489+00:00</updated>
    <content>EUVD-2026-268152</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-268152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-41768</id>
    <title>fkie_cve-2025-41768</title>
    <updated>2026-10-02T11:57:54.181519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An high privileged remote attacker can inject arbitrary content into the custom CSS field on the affected devices due to improper neutralization of input during web page generation ('Cross-site Scripting').</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-41768"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hrmx-9vmm-xj23</id>
    <title>GHSA-hrmx-9vmm-xj23</title>
    <updated>2026-10-02T11:57:54.181549+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>On an instance of TwinCAT 3 HMI Server running on a device an authenticated administrator can inject arbitrary content into the custom CSS field which is persisted on the device and later returned via the login page and error page.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hrmx-9vmm-xj23"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-106</id>
    <title>VDE-2025-106 — Beckhoff: XSS Vulnerability in TwinCAT 3 HMI Server</title>
    <updated>2026-10-02T11:57:54.181567+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An optional package of the TwinCAT 3 XAR installs the TwinCAT 3 HMI Server on a device. It provides a server configuration page which can be accessed by administrative users only. When such an administrator accesses the server configuration page it is possible to upload arbitrary content into the CUSTOM_CSS field which is then persisted on the device and later returned and rendered with each login and error page.
Please note that administrators have the access rights to modify any content on the HMI server, for example, via the server configuration page. Therefore, administrators would have to act maliciously to exploit this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-106"/>
  </entry>
</feed>
