<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T08:22:08.210836+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-255270</id>
    <title>EUVD-2026-255270</title>
    <updated>2026-10-08T08:22:08.257106+00:00</updated>
    <content>EUVD-2026-255270</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-255270"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-61924</id>
    <title>fkie_cve-2025-61924</title>
    <updated>2026-10-08T08:22:08.257146+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-61924"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wvpg-4wrh-5889</id>
    <title>GHSA-wvpg-4wrh-5889 — PrestaShop Checkout Target PayPal merchant account hijacking from backoffice</title>
    <updated>2026-10-08T08:22:08.257181+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: prestashop/ps_checkout</p>
<p>### Impact
Wrong usage of the PHP `array_search()` allows bypass of validation.</p>
<p>### Patches
The problem has been patched in versions:
- v4.4.1 for PrestaShop 1.7 (build number: 7.4.4.1)
- v4.4.1 for PrestaShop 8 (build number: 8.4.4.1)
- v5.0.5 for PrestaShop 1.7 (build number: 7.5.0.5)
- v5.0.5 for PrestaShop 8 (build number: 8.5.0.5)
- v5.0.5 for PrestaShop 9 (build number: 9.5.0.5)</p>
<p>Read the [Versioning policy](https://github.com/PrestaShopCorp/ps_checkout/wiki/Versioning) to learn more about the build number.</p>
<p>### Credits
[Léo CUNÉAZ](https://github.com/inem0o) reported this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wvpg-4wrh-5889"/>
  </entry>
</feed>
