<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:38:40.316676+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-263477</id>
    <title>EUVD-2026-263477</title>
    <updated>2026-10-06T16:38:40.368823+00:00</updated>
    <content>EUVD-2026-263477</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-263477"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-62192</id>
    <title>fkie_cve-2025-62192</title>
    <updated>2026-10-06T16:38:40.368859+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If exploited, information stored in the database may be obtained or altered by an authenticated user.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-62192"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-39hq-6vr8-7q37</id>
    <title>GHSA-39hq-6vr8-7q37</title>
    <updated>2026-10-06T16:38:40.368891+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If exploited, information stored in the database may be obtained or altered by an authenticated user.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-39hq-6vr8-7q37"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2025-000113</id>
    <title>jvndb-2025-000113</title>
    <updated>2026-10-06T16:38:40.368908+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GroupSession provided by Japan Total System Co.,Ltd. contains multiple vulnerabilities listed below.
&lt;ul&gt;&lt;li&gt;Stored cross-site scripting (CWE-79) - CVE-2025-53523&lt;/li&gt;
&lt;li&gt;Stored cross-site scripting (CWE-79) - CVE-2025-54407&lt;/li&gt;
&lt;li&gt;Reflected cross-site scripting (CWE-79) - CVE-2025-57883&lt;/li&gt;
&lt;li&gt;Cross-site request forgery (CWE-352) - CVE-2025-58576&lt;/li&gt;
&lt;li&gt;Authorization bypass through user-controlled key (CWE-639) - CVE-2025-61950&lt;/li&gt;
&lt;li&gt;Missing origin validation in webSockets (CWE-1385) - CVE-2025-61987&lt;/li&gt;&lt;li&gt;SQL injection (CWE-89) - CVE-2025-62192&lt;/li&gt;
&lt;li&gt;Initialization of a resource with an insecure default (CWE-1188) - CVE-2025-64781&lt;/li&gt;
&lt;li&gt;This can be exploited only when External page display restriction is set as "Do not limit", as in the initial configurationReflected cross-site scripting (CWE-79) - CVE-2025-65120&lt;/li&gt;
&lt;li&gt;Stored cross-site scripting (CWE-79) - CVE-2025-66284&lt;/li&gt;&lt;/ul&gt;
The following people reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2025-53523
Reporter: Shogo Iyota of GMO Cybersecurity by Ierae
        Gaku Mochizuki, Tsutomu Aramaki, and Taiga Shirakura of Mitsui Bussan Secure Directions, Inc.
        Natsumi Furukawa

CVE-2025-54407
Reporter: Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc.

CVE-2025-57883
Reporter: Tsuyuki Takumi of Mitsui Bussan Secure Directions, Inc.
        Ryo Sato

CVE-2025-58576
Rep…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2025-000113"/>
  </entry>
</feed>
