<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T16:07:13.788963+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-48509</id>
    <title>cnvd-2021-48509</title>
    <updated>2026-10-08T16:07:13.870091+00:00</updated>
    <content>cnvd-2021-48509</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-48509"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-28105</id>
    <title>EUVD-2026-28105</title>
    <updated>2026-10-08T16:07:13.870135+00:00</updated>
    <content>EUVD-2026-28105</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-28105"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-32735</id>
    <title>fkie_cve-2021-32735</title>
    <updated>2026-10-08T16:07:13.870151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in page titles as it is. This could be used for cross-site scripting (XSS) attacks. Malicious authenticated Panel users can escalate their privileges if they get access to the Panel session of an admin user. Visitors without Panel access can use the attack vector if the site allows changing site data from a frontend form. Kirby 3.5.7 patches the vulnerability. As a partial workaround, site administrators can protect against attacks from visitors without Panel access by validating or sanitizing provided data from the frontend form.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-32735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2f2w-349x-vrqm</id>
    <title>GHSA-2f2w-349x-vrqm — Cross-site scripting (XSS) from field and configuration text displayed in the Panel</title>
    <updated>2026-10-08T16:07:13.870190+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: getkirby/cms</p>
<p>On Saturday, @hdodov reported that the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in page titles as it is. This could be used for cross-site scripting (XSS) attacks.</p>
<p>We used his report as an opportunity to find and fix XSS issues related to dynamic site content throughout the Panel codebase.</p>
<p>### Impact</p>
<p>Cross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the Panel session of other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim.</p>
<p>Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible.</p>
<p>Visitors without Panel access can only use this attack vector if your site allows changing site data from a frontend form (for example user self-registration or the creation of pages from a contact or other frontend form). If you validate or sanitize the provided form data, you are already protected against such attacks by external visitors.</p>
<p>### Patches</p>
<p>[Kirby 3.5.7](https://github.com/getkirby/kirby/releases/tag/3.5.7) contains patches for the following issues we found during our investigation:</p>
<p>- Some translated error and info messages contain placeholders to dynamically insert informati…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2f2w-349x-vrqm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-32735</id>
    <title>gsd-2021-32735</title>
    <updated>2026-10-08T16:07:13.870245+00:00</updated>
    <content>gsd-2021-32735</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-32735"/>
  </entry>
</feed>
