<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T09:37:18.370987+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-00972</id>
    <title>bdu:2024-00972</title>
    <updated>2026-10-08T09:37:18.374889+00:00</updated>
    <content>bdu:2024-00972</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-00972"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-213842</id>
    <title>EUVD-2026-213842</title>
    <updated>2026-10-08T09:37:18.374923+00:00</updated>
    <content>EUVD-2026-213842</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-213842"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-29213</id>
    <title>fkie_cve-2023-29213</title>
    <updated>2026-10-08T09:37:18.374937+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of `org.xwiki.platform:xwiki-platform-logging-ui` it is possible to trick a user with programming rights into visiting a constructed url where e.g., by embedding an image with this URL in a document that is viewed by a user with programming rights which will evaluate an expression in the constructed url and execute it. This issue has been addressed in versions 13.10.11, 14.4.7, and 14.10. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-29213"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4655-wh7v-3vmg</id>
    <title>GHSA-4655-wh7v-3vmg — org.xwiki.platform:xwiki-platform-logging-ui Eval Injection vulnerability</title>
    <updated>2026-10-08T09:37:18.374966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.xwiki.platform:xwiki-platform-logging-ui</p>
<p>### Impact</p>
<p>#### Steps to reproduce:</p>
<p>It is possible to trick a user with programming rights into visiting &lt;xwiki-host&gt;/xwiki/bin/view/XWiki/LoggingAdmin?loggeraction_set=1&amp;logger_name=%7B%7Bcache%7D%7D%7B%7Bgroovy%7D%7Dnew+File%28%22%2Ftmp%2Fexploit.txt%22%29.withWriter+%7B+out+-%3E+out.println%28%22created+from+notification+filter+preferences%21%22%29%3B+%7D%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fcache%7D%7D&amp;logger_level=TRACE where &lt;xwiki-host&gt; is the URL of your XWiki installation, e.g., by embedding an image with this URL in a document that is viewed by a user with programming rights.</p>
<p>#### Expected result:</p>
<p>No file in /tmp/exploit.txt has been created.</p>
<p>#### Actual result:</p>
<p>The file `/tmp/exploit.txt` is been created with content "created from notification filter preferences!". This demonstrates a CSRF remote code execution vulnerability that could also be used for privilege escalation or data leaks (if the XWiki installation can reach remote hosts).</p>
<p>### Patches
The problem has been patched on XWiki 14.4.7, and 14.10.</p>
<p>### Workarounds
The issue can be fixed manually applying this [patch](https://github.com/xwiki/xwiki-platform/commit/49fdfd633ddfa346c522d2fe71754dc72c9496ca).</p>
<p>### References
- https://jira.xwiki.org/browse/XWIKI-20291
- https://github.com/xwiki/xwiki-platform/commit/49fdfd633ddfa346c522d2fe71754dc72c9496ca</p>
<p>### For more information
If you have any questions or comments about this advisory:</p>
<p>*    Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)
*…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4655-wh7v-3vmg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-29213</id>
    <title>gsd-2023-29213</title>
    <updated>2026-10-08T09:37:18.375015+00:00</updated>
    <content>gsd-2023-29213</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-29213"/>
  </entry>
</feed>
