<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T13:15:51.112875+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2022-45137</id>
    <title>CVE-2022-45137 — WAGO: Reflective Cross-Site Scripting</title>
    <updated>2026-10-07T13:15:51.148676+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> WAGO Compact Controller CC100 (751-9301), WAGO Edge Controller (752-8303/8000-002), WAGO PFC100 (750-81xx/xxx-xxx), WAGO PFC200 (750-82xx/xxx-xxx), WAGO Touch Panel 600 Advanced Line (762-5xxx), WAGO Touch Panel 600 Marine Line (762-6xxx), WAGO Touch Panel 600 Standard Line (762-4xxx)</p>
<p>The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no impact of availability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2022-45137"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-060</id>
    <title>VDE-2022-060 — WAGO: Multiple vulnerabilities in web-based management of multiple products</title>
    <updated>2026-10-07T13:15:51.148757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates.
The configuration backend can in some cases be used without authentication and to write data with root privileges. Additionally, the web-based management suffers a CORS misconfiguration and allows reflected XSS (Cross-Site Scripting) attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-060"/>
  </entry>
</feed>
