<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T19:27:16.250664+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-235743</id>
    <title>EUVD-2026-235743</title>
    <updated>2026-10-10T19:27:16.255571+00:00</updated>
    <content>EUVD-2026-235743</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-235743"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-46347</id>
    <title>fkie_cve-2025-46347</title>
    <updated>2026-10-10T19:27:16.255607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used to write a file with a PHP extension, which then can be browsed to in order to execute arbitrary code on the server, resulting in a full compromise of the server. This could potentially be performed unwittingly by a user. This issue has been patched in version 4.5.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-46347"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-88xg-v53p-fpvf</id>
    <title>GHSA-88xg-v53p-fpvf — YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution</title>
    <updated>2026-10-10T19:27:16.255641+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: yeswiki/yeswiki</p>
<p>### Summary
An arbitrary file write can be used to write a file with a PHP extension, which then can be browsed to in order to execute arbitrary code on the server.</p>
<p>All testing was performed on a local docker setup running the latest version of the application.</p>
<p>### PoC
Proof of Concept</p>
<p>Navigate to `http://localhost:8085/?LookWiki` which allows you to click `Create a new Graphical configuration` where you specify some parameters and then click `Save`.</p>
<p>![LookWiki](https://github.com/user-attachments/assets/11c638ec-b700-483a-91fb-2d83107c2c69)</p>
<p>After clicking save, this request is made (most headers removed for clarity):</p>
<p>```
POST /?api/templates/custom-presets/test.css HTTP/1.1
Host: localhost:8085</p>
<p>primary-color=%230c5d6a&amp;secondary-color-1=%23d8604c&amp;secondary-color-2=%23d78958&amp;neutral-color=%234e5056&amp;neutral-soft-color=%2357575c&amp;neutral-light-color=%23f2f2f2&amp;main-text-fontsize=17px&amp;main-text-fontfamily=%22Nunito%22%2C+sans-serif&amp;main-title-fontfamily='Nunito'%2C+sans-serif
```</p>
<p>This request writes the file `test.css` to disk with the contents (abbreviated)
```
:root {
  --primary-color: #0c5d6a;
  --secondary-color-1: #d8604c;
  --secondary-color-2: #d78958;
  --neutral-color: #4e5056;
  --neutral-soft-color: #57575c;
  --neutral-light-color: #f2f2f2;
  --main-text-fontsize: 17px;
  --main-text-fontfamily: "Nunito", sans-serif;
  --main-title-fontfamily: 'Nunito', sans-serif;
}
```</p>
<p>To exploit this, utilize a proxy tool to intercept the the first request and change t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-88xg-v53p-fpvf"/>
  </entry>
</feed>
