<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T20:12:01.667895+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-186125</id>
    <title>EUVD-2026-186125</title>
    <updated>2026-10-06T20:12:01.672262+00:00</updated>
    <content>EUVD-2026-186125</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-186125"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45604</id>
    <title>fkie_cve-2024-45604</title>
    <updated>2026-10-06T20:12:01.672315+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-45604"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4p75-5p53-65m9</id>
    <title>GHSA-4p75-5p53-65m9 — Contao affected by directory traversal in the file selector widget</title>
    <updated>2026-10-06T20:12:01.672363+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: contao/core-bundle</p>
<p>### Impact</p>
<p>Back end users can list files outside their file mounts or the document root in the FileSelector widget.</p>
<p>### Patches</p>
<p>Update to Contao 4.13.49.</p>
<p>### Workarounds</p>
<p>None.</p>
<p>### References</p>
<p>https://contao.org/en/security-advisories/directory-traversal-in-the-fileselector-widget</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).</p>
<p>### Credits</p>
<p>Thanks to Jakob Steeg from usd AG for reporting this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4p75-5p53-65m9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2152</id>
    <title>WID-SEC-W-2024-2152 — Contao: Mehrere Schwachstellen</title>
    <updated>2026-10-06T20:12:01.672424+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in Contao ausnutzen, um beliebigen Code auszuführen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2152"/>
  </entry>
</feed>
