<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T13:32:28.722705+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-358421</id>
    <title>EUVD-2026-358421</title>
    <updated>2026-10-06T13:32:28.725683+00:00</updated>
    <content>EUVD-2026-358421</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-358421"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61807</id>
    <title>fkie_cve-2026-61807</title>
    <updated>2026-10-06T13:32:28.725728+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side code reads the browser-decoded countId, uses it as a selector, concatenates countId.substring(1) into an HTML string, and passes the string to jQuery .after(). A crafted name can therefore execute JavaScript when an authenticated user views the manufacturer detail page or supplier detail page, potentially exposing data or actions available to that session. This issue is fixed in version 8.6.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-61807"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c8qc-wf67-342w</id>
    <title>GHSA-c8qc-wf67-342w — Snipe-IT: Stored DOM XSS via table selected-count IDs</title>
    <updated>2026-10-06T13:32:28.725786+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: snipe/snipe-it</p>
<p>### Impact
The table component derives data-selected-count-id from the component $name value. On manufacturer and supplier detail pages, stored manufacturer or supplier names are passed into affected table components as that name value. The client-side JavaScript later reads the browser-decoded data-selected-count-id, uses it as a selector, and concatenates countId.substring(1) directly into an HTML string passed to jQuery .after().</p>
<p>Affected commit:</p>
<p>`b224cc636c6780386e3f73f03d1171f52ab4c37a`</p>
<p>Example payload for a manufacturer or supplier name:
`x[foo="&gt;&lt;svg/onload=alert(1)&gt;"]&gt;`</p>
<p>The issue appears to involve the following flow:</p>
<p>Stored supplier/manufacturer name
-&gt; table component data-selected-count-id
-&gt; browser decodes the attribute
-&gt; JavaScript reads countId
-&gt; countId is used as a selector
-&gt; countId.substring(1) is concatenated into HTML
-&gt; jQuery .after() inserts attacker-controlled markup
-&gt; JavaScript executes in the victim's browser</p>
<p>Potential impact includes arbitrary JavaScript execution in the browser of an authenticated Snipe-IT user who views the affected supplier or manufacturer detail page. If the victim has elevated privileges, this may allow access to data or actions available to that user's session.</p>
<p>### Patches
Patched in https://github.com/grokability/snipe-it/commit/d12ad3d53869443b96b663ba3ce2673ef343da71</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c8qc-wf67-342w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2073</id>
    <title>WID-SEC-W-2026-2073 — Snipe-IT: Mehrere Schwachstellen</title>
    <updated>2026-10-06T13:32:28.725863+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Snipe-IT ausnutzen, um Dateien zu manipulieren, um Sicherheitsvorkehrungen zu umgehen, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2073"/>
  </entry>
</feed>
