<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T13:56:28.103348+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-57368</id>
    <title>EUVD-2026-57368</title>
    <updated>2026-10-08T13:56:28.163289+00:00</updated>
    <content>EUVD-2026-57368</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-57368"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-15782</id>
    <title>fkie_cve-2019-15782</title>
    <updated>2026-10-08T13:56:28.163327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-15782"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gjh4-fcv3-whpq</id>
    <title>GHSA-gjh4-fcv3-whpq — Cross-Site Scripting in webtorrent</title>
    <updated>2026-10-08T13:56:28.163360+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: webtorrent</p>
<p>Versions of `webtorrent` prior to 0.107.6 are vulnerable to Cross-Site Scripting. `webtorrent` servers started with `torrent.createServer()` lists a torrent's title and files in the index page without sanitization. This allows attackers to execute arbitrary JavaScript in the victim's browser through files with names containing the malicious payload. The issue is mitigated due to the fact that the server only allows fetching data pieces from the torrent.</p>
<p>## Recommendation</p>
<p>Upgrade to version 0.107.6 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gjh4-fcv3-whpq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-15782</id>
    <title>gsd-2019-15782</title>
    <updated>2026-10-08T13:56:28.163389+00:00</updated>
    <content>gsd-2019-15782</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-15782"/>
  </entry>
</feed>
