<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:39:45.200326+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-253447</id>
    <title>EUVD-2026-253447</title>
    <updated>2026-10-04T15:39:45.259479+00:00</updated>
    <content>EUVD-2026-253447</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-253447"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59839</id>
    <title>fkie_cve-2025-59839</title>
    <updated>2026-10-04T15:39:45.259519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext. This issue has been patched via commit 4e075d3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-59839"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4j5h-mvj3-m48v</id>
    <title>GHSA-4j5h-mvj3-m48v — Star Citizen  EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes</title>
    <updated>2026-10-04T15:39:45.259553+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: starcitizenwiki/embedvideo</p>
<p>### Summary
The EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext.</p>
<p>### Details</p>
<p>The attributes of an iframe are populated with the value of an unreserved data attribute (`data-iframeconfig`) that can be set via wikitext:
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/blob/440fb331a84b2050f4cc084c1d31d58a1d1c202d/resources/ext.embedVideo.videolink.js#L5-L20
Similar code is also present here:
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/blob/440fb331a84b2050f4cc084c1d31d58a1d1c202d/resources/modules/iframe.js#L139-L155</p>
<p>It is possible to execute JS through attributes like `onload` or `onmouseenter`.</p>
<p>### PoC</p>
<p>1. Create a page with the following contents:
```html
&lt;div class="embedvideo-evl" data-iframeconfig='{"onload": "alert(1)"}'&gt;Click me!&lt;/div&gt;
&lt;evlplayer&gt;&lt;/evlplayer&gt;
```
2. Click on the "Click me!" text
3. Click on the "Load video" button below
&lt;img width="855" height="404" alt="image" src="https://github.com/user-attachments/assets/afb3839a-012c-4e90-a208-a6137b704ccd" /&gt;</p>
<p>### Impact
Arbitrary HTML can be inserted into the DOM by any user, allowing for JavaScript to be executed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4j5h-mvj3-m48v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2341</id>
    <title>WID-SEC-W-2025-2341 — MediaWiki Extensions: Mehrere Schwachstellen ermöglichen Codeausführung</title>
    <updated>2026-10-04T15:39:45.259594+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um beliebigen Code oder SQL-Befehle auszuführen, Cross-Site-Scripting-Angriffe durchzuführen und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2341"/>
  </entry>
</feed>
