<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T13:46:15.970694+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2023-07920</id>
    <title>cnvd-2023-07920</title>
    <updated>2026-10-09T13:46:17.783629+00:00</updated>
    <content>cnvd-2023-07920</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2023-07920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-225482</id>
    <title>EUVD-2026-225482</title>
    <updated>2026-10-09T13:46:17.783669+00:00</updated>
    <content>EUVD-2026-225482</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-225482"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0610</id>
    <title>fkie_cve-2023-0610</title>
    <updated>2026-10-09T13:46:17.783683+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-0610"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mrqx-mjc4-vfh3</id>
    <title>GHSA-mrqx-mjc4-vfh3 — wallabag subject to Improper Authorization via annotations</title>
    <updated>2026-10-09T13:46:17.783713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: wallabag/wallabag</p>
<p>### Impact
The annotations feature lets users add annotations on highlighted parts of an entry.</p>
<p>The controller does not validate authorization on `PUT` and `DELETE` requests which lets a logged user modify or delete any annotation using their ID on their endpoints `example.org/annotations/{id}`.</p>
<p>These vulnerable requests also disclose highlighted parts of the entry to the attacker.</p>
<p>You should immediately patch your instance to version 2.5.3 or higher if you have more than one user and/or having open registration.</p>
<p>### Resolution</p>
<p>A user check is now done in the vulnerable methods before applying change on an annotation.</p>
<p>The Annotation retrieval through a `ParamConverter` has also been replaced with a call to the `AnnotationRepository` in order to prevent any information disclosure through response discrepancy.</p>
<p>### Workarounds</p>
<p>### Credits</p>
<p>We would like to thank @bAuh0lz for reporting this issue through huntr.dev.</p>
<p>Reference: https://huntr.dev/bounties/8fdd9b31-d89b-4bbe-9557-20b960faf926/</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mrqx-mjc4-vfh3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-0610</id>
    <title>gsd-2023-0610</title>
    <updated>2026-10-09T13:46:17.783750+00:00</updated>
    <content>gsd-2023-0610</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-0610"/>
  </entry>
</feed>
