<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T01:47:23.669173+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-5830</id>
    <title>EUVD-2026-5830</title>
    <updated>2026-10-07T01:47:23.718777+00:00</updated>
    <content>EUVD-2026-5830</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-5830"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-37156</id>
    <title>fkie_cve-2024-37156</title>
    <updated>2026-10-07T01:47:23.718817+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which leads to XSS. This vulnerability is fixed in 2.5.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-37156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rrvc-c7xg-7cf3</id>
    <title>GHSA-rrvc-c7xg-7cf3 — TokenController formName not sanitized in hidden input</title>
    <updated>2026-10-07T01:47:23.718851+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: sulu/form-bundle</p>
<p>### Impact</p>
<p>TokenController get parameter formName not sanitized in returned input field leads to XSS.</p>
<p>_What kind of vulnerability is it? Who is impacted?_</p>
<p>### Patches</p>
<p>_Has the problem been patched? What versions should users upgrade to?_</p>
<p>### Workarounds</p>
<p>_Is there a way for users to fix or remediate the vulnerability without upgrading?_</p>
<p>Create a custom Symfony Request listener which checks for the get value of `form` for the TokenController and if not valid stop the request dispatching and return a error status code.</p>
<p>### References</p>
<p>_Are there any links users can visit to find out more?_</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rrvc-c7xg-7cf3"/>
  </entry>
</feed>
