<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T22:42:34.008829+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2015-03619</id>
    <title>cnvd-2015-03619</title>
    <updated>2026-10-08T22:42:34.093987+00:00</updated>
    <content>cnvd-2015-03619</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2015-03619"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-91485</id>
    <title>EUVD-2026-91485</title>
    <updated>2026-10-08T22:42:34.094032+00:00</updated>
    <content>EUVD-2026-91485</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-91485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2015-2944</id>
    <title>fkie_cve-2015-2944</title>
    <updated>2026-10-08T22:42:34.094046+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2015-2944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rxvx-44w5-44r7</id>
    <title>GHSA-rxvx-44w5-44r7 — Improper Neutralization of Input During Web Page Generation in Apache Sling</title>
    <updated>2026-10-08T22:42:34.094079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.sling:org.apache.sling.api, Maven: org.apache.sling:org.apache.sling.servlets.post</p>
<p>Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rxvx-44w5-44r7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2015-2944</id>
    <title>gsd-2015-2944</title>
    <updated>2026-10-08T22:42:34.094106+00:00</updated>
    <content>gsd-2015-2944</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2015-2944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2015-000069</id>
    <title>jvndb-2015-000069</title>
    <updated>2026-10-08T22:42:34.094119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Sling is an open source web application framework provided by The Apache Software Foundation.
Sling API and Servlet Post components included in Apache Sling contain a cross-site scripting vulnerability (CWE-79) in the error page and the generation of the job completion.

MORI Shingo and Toshiharu Sugiyama of DeNA Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2015-000069"/>
  </entry>
</feed>
