<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T12:46:53.201394+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248276</id>
    <title>EUVD-2026-248276</title>
    <updated>2026-10-07T12:46:53.249921+00:00</updated>
    <content>EUVD-2026-248276</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248276"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54128</id>
    <title>fkie_cve-2025-54128</title>
    <updated>2026-10-07T12:46:53.249963+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks. The contentSecurityPolicy value is explicitly disabled in the application's Helmet configuration in app.js. This is fixed in version 11.0.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-54128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-59g8-h59f-8hjp</id>
    <title>GHSA-59g8-h59f-8hjp — NodeJS version of HAX CMS Has Disabled Content Security Policy That Enables Cross-Site Scripting</title>
    <updated>2026-10-07T12:46:53.250018+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @haxtheweb/haxcms-nodejs</p>
<p>### Summary
The NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks.</p>
<p>### Details
The `contentSecurityPolicy` value is explicitly disabled in the application's Helmet configuration in `app.js`.</p>
<p>![permissive-csp-code](https://github.com/user-attachments/assets/8ec6c63c-9f9f-413e-be7e-ed14913da91c)</p>
<p>#### Affected Resources
- [app.js:52](https://github.com/haxtheweb/haxcms-nodejs/blob/b1f95880b42fea6ed07855b5804b29b182ec5e07/src/app.js#L52)</p>
<p>### PoC
To reproduce this vulnerability, [install](https://github.com/haxtheweb/haxcms-nodejs) HAX CMS NodeJS. The application will load without a CSP configured.</p>
<p>### Impact
In conjunction with an XSS vulnerability, an attacker could execute arbitrary scripts and exfiltrate data, including session tokens and sensitive local data.</p>
<p>#### Additional Information
- [OWASP: Content Security Policy](https://cheatsheetseries.owasp.org/cheatsheets/Content_Security_Policy_Cheat_Sheet.html)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-59g8-h59f-8hjp"/>
  </entry>
</feed>
