<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:43:45.336588+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-291671</id>
    <title>EUVD-2026-291671</title>
    <updated>2026-10-04T01:43:45.339243+00:00</updated>
    <content>EUVD-2026-291671</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-291671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40104</id>
    <title>fkie_cve-2026-40104</title>
    <updated>2026-10-04T01:43:45.339275+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc-1, 17.0.0-rc-1 and 17.5.0-rc-1 and prior include a resource exhaustion vulnerability in REST API endpoints such as /xwiki/rest/wikis/xwiki/spaces/AnnotationCode/pages/AnnotationConfig/objects/AnnotationCode.AnnotationConfig/0/properties, which list all available pages as part of the metadata for database list properties without applying query limits. On large wikis, this can exhaust available server resources. This issue has been patched in versions 16.10.16, 17.4.8 and 17.10.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40104"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mrqg-xmgm-rc5g</id>
    <title>GHSA-mrqg-xmgm-rc5g — XWiki's REST APIs can list all pages/spaces, leading to unavailability</title>
    <updated>2026-10-04T01:43:45.339308+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.xwiki.platform:xwiki-platform-oldcore, Maven: org.xwiki.platform:xwiki-platform-legacy-oldcore</p>
<p>### Impact
REST API endpoints like `/xwiki/rest/wikis/xwiki/spaces/AnnotationCode/pages/AnnotationConfig/objects/AnnotationCode.AnnotationConfig/0/properties` list all available pages as part of the metadata for database list properties, which can exhaust available resources on large wikis.</p>
<p>### Patches
This problem has been patched by applying the configured query limit also to the available values for database list properties in XWiki 16.10.16, 17.4.8 and 17.10.1.</p>
<p>### Workarounds
We're not aware of any workarounds apart from upgrading the affected modules.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mrqg-xmgm-rc5g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1089</id>
    <title>WID-SEC-W-2026-1089 — xwiki: Mehrere Schwachstellen</title>
    <updated>2026-10-04T01:43:45.339340+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in xwiki ausnutzen, um einen Denial of Service Angriff durchzuführen, und um einen Cross-Site Scripting Angriff durchzuühren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1089"/>
  </entry>
</feed>
