<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:32:21.452843+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-22701</id>
    <title>cnvd-2025-22701</title>
    <updated>2026-10-02T17:32:21.516479+00:00</updated>
    <content>cnvd-2025-22701</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-22701"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-245941</id>
    <title>EUVD-2026-245941</title>
    <updated>2026-10-02T17:32:21.516527+00:00</updated>
    <content>EUVD-2026-245941</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-245941"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52902</id>
    <title>fkie_cve-2025-52902</title>
    <updated>2026-10-02T17:32:21.516557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of File Browser prior to v2.33.7 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser. Version 2.33.7 contains a fix for the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-52902"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4wx8-5gm2-2j97</id>
    <title>GHSA-4wx8-5gm2-2j97 — filebrowser allows Stored Cross-Site Scripting through the Markdown preview function</title>
    <updated>2026-10-02T17:32:21.516604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser</p>
<p>## Summary ##</p>
<p>The Markdown preview function of File Browser v2.32.0 is vulnerable to *Stored Cross-Site-Scripting (XSS)*. Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser</p>
<p>## Impact ##</p>
<p>A user can upload a malicious Markdown file to the application which can contain arbitrary HTML code. If another user within the same scope clicks on that file, a rendered preview is opened. JavaScript code that has been included will be executed.</p>
<p>Malicious actions that are possible include:
 
  * Obtaining a user's session token
  * Elevating the attacker's privileges, if the victim is an administrator (e.g., gaining command execution rights)</p>
<p>## Vulnerability Description ##</p>
<p>Most Markdown parsers accept arbitrary HTML in a document and try rendering it accordingly. For instance, if one creates a file called `xss.md` with the following content:</p>
<p>```markdown
# Hallo</p>
<p>&lt;b&gt;foo&lt;/b&gt;</p>
<p>&lt;img src="xx" onerror=alert(9)&gt;
&lt;i&gt;bar&lt;/i&gt;
```</p>
<p>Bold and italic text will be rendered. Also, the renderer used in File Browser will try to display the image and execute the code in the `onerror` event handler.</p>
<p>## Proof of Concept ##</p>
<p>The screenshot shows that the code from the file mentioned above has actually been executed in the victim's browser:</p>
<p>![JavaScript code being executed in the Markdown Preview](https://github.com/user-attachments/assets/3a3b9920-fbd8-433f-a016-ea77f5f68851)</p>
<p>## Recommended Countermeasures ##</p>
<p>The most thorough fix would be to reconf…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4wx8-5gm2-2j97"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</id>
    <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
    <updated>2026-10-02T17:32:21.516734+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1"/>
  </entry>
</feed>
