<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T04:07:01.811192+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-254169</id>
    <title>EUVD-2026-254169</title>
    <updated>2026-10-07T04:07:01.814318+00:00</updated>
    <content>EUVD-2026-254169</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-254169"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59943</id>
    <title>fkie_cve-2025-59943</title>
    <updated>2026-10-07T04:07:01.814352+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multiple distinct accounts to be created with the same email. Because email is often used as an identifier for password resets, notifications, and administrative actions, this flaw can cause account ambiguity and, in certain configurations, may lead to privilege escalation or account takeover. This issue is fixed in version 4.0.13.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-59943"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9wj2-4hcm-r74j</id>
    <title>GHSA-9wj2-4hcm-r74j — phpMyFAQ duplicate email registration allows multiple accounts with the same email</title>
    <updated>2026-10-07T04:07:01.814385+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: thorsten/phpmyfaq</p>
<p>### Summary
phpMyFAQ does not enforce uniqueness of email addresses during user registration. This allows multiple distinct accounts to be created with the same email. Because email is often used as an identifier for password resets, notifications, and administrative actions, this flaw can cause account ambiguity and, in certain configurations, may lead to privilege escalation or account takeover.</p>
<p>### Details
An account management logic flaw in phpMyFAQ allows attackers to register multiple accounts under the same email address. If email is used for password reset or administrative flows, this may result in account takeover, loss of accountability, and abuse of business logic.
### PoC</p>
<p>1.Register  a user with email test@example.com
2.Register another user with the same email.
3.Both accounts appear in /admin/?action=user&amp;user_action=listallusers.
&lt;img width="1150" height="628" alt="image" src="https://github.com/user-attachments/assets/8c19f01a-e897-4ca7-b3f8-fcf83e6ff952" /&gt;</p>
<p>### Impact</p>
<p>-Data integrity loss: Multiple accounts mapped to one email break auditability.
-Password reset ambiguity: If reset flow relies on email only, attackers can target or take over accounts.
-Privilege escalation: If one account with the same email has admin privileges, an attacker controlling the email may escalate.
-Spam / DoS: Attackers can mass-register accounts with a single email to pollute the system.</p>
<p>This is a business logic / authentication vulnerability. Impacted users are anyone re…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9wj2-4hcm-r74j"/>
  </entry>
</feed>
