<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T01:59:17.038958+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-04572</id>
    <title>bdu:2021-04572</title>
    <updated>2026-10-08T01:59:17.042181+00:00</updated>
    <content>bdu:2021-04572</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-04572"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-255947</id>
    <title>EUVD-2026-255947</title>
    <updated>2026-10-08T01:59:17.042213+00:00</updated>
    <content>EUVD-2026-255947</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-255947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-32648</id>
    <title>fkie_cve-2021-32648</title>
    <updated>2026-10-08T01:59:17.042228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-32648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mxr5-mc97-63rc</id>
    <title>GHSA-mxr5-mc97-63rc — Account Takeover in Octobercms</title>
    <updated>2026-10-08T01:59:17.042257+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: october/system</p>
<p>### Impact</p>
<p>An attacker can request an account password reset and then gain access to the account using a specially crafted request.</p>
<p>- To exploit this vulnerability, an attacker must know the username of an administrator and have access to the password reset form.</p>
<p>### Patches</p>
<p>- Issue has been patched in Build 472 and v1.1.5
- [Shortened patch instructions](https://github.com/daftspunk/CVE-2021-32648)</p>
<p>### Workarounds</p>
<p>Apply https://github.com/octobercms/library/commit/016a297b1bec55d2e53bc889458ed2cb5c3e9374 and https://github.com/octobercms/library/commit/5bd1a28140b825baebe6becd4f7562299d3de3b9 to your installation manually if you are unable to upgrade.</p>
<p>[**Update 2022-01-20**] [Shortened patch instructions](https://github.com/daftspunk/CVE-2021-32648) can be found here.</p>
<p>### Recommendations</p>
<p>We recommend the following steps to make sure your server stays secure:</p>
<p>- Keep server OS and system software up to date.
- Keep October CMS software up to date.
- Use a multi-factor authentication plugin.
- Change the [default backend URL](https://github.com/octobercms/october/blob/1.1/config/cms.php#L39) or block public access to the backend area.
- Include the [Roave/SecurityAdvisories](https://github.com/Roave/SecurityAdvisories) Composer package to ensure that your application doesn't have installed dependencies with known security vulnerabilities.</p>
<p>### References</p>
<p>Bugs found as part of Solar Security CMS Research. Credits to:
• Andrey Basarygin
• Andrey Guzei
• Mikhail Khrame…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mxr5-mc97-63rc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-32648</id>
    <title>gsd-2021-32648</title>
    <updated>2026-10-08T01:59:17.042308+00:00</updated>
    <content>gsd-2021-32648</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-32648"/>
  </entry>
</feed>
