<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T18:21:08.572369+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-186130</id>
    <title>EUVD-2026-186130</title>
    <updated>2026-10-06T18:21:08.635107+00:00</updated>
    <content>EUVD-2026-186130</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-186130"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45398</id>
    <title>fkie_cve-2024-45398</title>
    <updated>2026-10-06T18:21:08.635161+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are advised to configure their web server so it does not execute PHP files and other scripts in the Contao file upload directory.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-45398"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vm6r-j788-hjh5</id>
    <title>GHSA-vm6r-j788-hjh5 — Contao affected by remote command execution through file upload</title>
    <updated>2026-10-06T18:21:08.635231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: contao/core-bundle</p>
<p>### Impact</p>
<p>Back end users with access to the file manager can upload malicious files and execute them on the server.</p>
<p>### Patches</p>
<p>Update to Contao 4.13.49, 5.3.15 or 5.4.3.</p>
<p>### Workarounds</p>
<p>Configure your web server so it does not execute PHP files and other scripts in the Contao file upload directory.</p>
<p>### References</p>
<p>https://contao.org/en/security-advisories/remote-command-execution-through-file-uploads</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).</p>
<p>### Credits</p>
<p>Thanks to Jakob Steeg from usd AG for reporting this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vm6r-j788-hjh5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2152</id>
    <title>WID-SEC-W-2024-2152 — Contao: Mehrere Schwachstellen</title>
    <updated>2026-10-06T18:21:08.635300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in Contao ausnutzen, um beliebigen Code auszuführen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2152"/>
  </entry>
</feed>
