<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T19:17:45.085265+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-05357</id>
    <title>bdu:2025-05357</title>
    <updated>2026-10-09T19:17:45.088624+00:00</updated>
    <content>bdu:2025-05357</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-05357"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-235939</id>
    <title>EUVD-2026-235939</title>
    <updated>2026-10-09T19:17:45.088659+00:00</updated>
    <content>EUVD-2026-235939</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-235939"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-32970</id>
    <title>fkie_cve-2025-32970</title>
    <updated>2026-10-09T19:17:45.088673+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, an open redirect vulnerability in the HTML conversion request filter allows attackers to construct URLs on an XWiki instance that redirects to any URL. This issue has been patched in versions 15.10.13, 16.4.4, and 16.8.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-32970"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pjhg-9wr9-rj96</id>
    <title>GHSA-pjhg-9wr9-rj96 — org.xwiki.platform:xwiki-platform-wysiwyg-api Open Redirect vulnerability</title>
    <updated>2026-10-09T19:17:45.088702+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.xwiki.platform:xwiki-platform-wysiwyg-api</p>
<p>### Impact</p>
<p>An open redirect vulnerability in the HTML conversion request filter allows attackers to construct URLs on an XWiki instance that redirect to any URL. To reproduce, open `&lt;xwiki-host&gt;/xwiki/bin/view/Main/?foo=bar&amp;foo_syntax=invalid&amp;RequiresHTMLConversion=foo&amp;xerror=https://www.example.com/` where `&lt;xwiki-host&gt;` is the URL of your XWiki installation.</p>
<p>### Patches
This bug has been fixed in XWiki 15.10.13, 16.4.4 and 16.8.0 by validating the domain of the redirect URL against the configured safe domains and the current request's domain.</p>
<p>### Workarounds
A web application firewall could be configured to reject requests with the `xerror` parameter as from our analysis this parameter isn't used anymore. For requests with the `RequiresHTMLConversion` parameter set, the referrer URL should be checked if it points to the XWiki installation. Apart from that, we're not aware of any workarounds.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pjhg-9wr9-rj96"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0898</id>
    <title>WID-SEC-W-2025-0898 — xwiki: Mehrere Schwachstellen</title>
    <updated>2026-10-09T19:17:45.088735+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in xwiki ausnutzen, um falsche Informationen darzustellen, einen Denial-of-Service auszulösen, Benutzerrechte zu erlangen oder Cross-Site-Scripting durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0898"/>
  </entry>
</feed>
