<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T05:14:16.972032+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-6466</id>
    <title>EUVD-2026-6466</title>
    <updated>2026-10-06T05:14:16.975895+00:00</updated>
    <content>EUVD-2026-6466</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-6466"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-41676</id>
    <title>fkie_cve-2024-41676</title>
    <updated>2026-10-06T05:14:16.975939+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases.
But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. The problem is patched with Version 20.10.1 or higher.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-41676"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5vrp-638w-p8m2</id>
    <title>GHSA-5vrp-638w-p8m2 — Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs</title>
    <updated>2026-10-06T05:14:16.975988+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: openmage/magento-lts</p>
<p>### Impact</p>
<p>This XSS vulnerability is about the system configs
* design/header/welcome
* design/header/logo_src
* design/header/logo_src_small
* design/header/logo_alt</p>
<p>They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases.
But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript.</p>
<p>While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege.</p>
<p>### Patches
_Has the problem been patched? What versions should users upgrade to?_</p>
<p>The problem is patched with Version 20.10.1 or higher.</p>
<p>### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_</p>
<p>Possible mitigations are
* Restricting access to the System Configs 
* checking templates where these settings are used to apply proper html filtering</p>
<p>### For Users relying on this possibility</p>
<p>Some Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced `-&gt;getUnescapedValue()` method on this escaped elements. Developers should have a look at the newly introduced `Mage_Core_Model_Security_HtmlEscapedString`</p>
<p>### Credit</p>
<p>Credit goes to  Aakash Adhikari @justlife4x4 for finding this issue</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5vrp-638w-p8m2"/>
  </entry>
</feed>
