<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T18:46:13.482381+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261861</id>
    <title>EUVD-2026-261861</title>
    <updated>2026-10-08T18:46:13.538428+00:00</updated>
    <content>EUVD-2026-261861</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261861"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64049</id>
    <title>fkie_cve-2025-64049</title>
    <updated>2026-10-08T18:46:13.538483+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote users to inject arbitrary web script or HTML via the Output code field in modules. The payload is executed when a user views or edits an article by adding slice that uses the compromised module.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-64049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vqc7-7fj4-3fm3</id>
    <title>GHSA-vqc7-7fj4-3fm3 — REDAXO CMS is vulnerable to XSS through its module management component</title>
    <updated>2026-10-08T18:46:13.538529+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: redaxo/source</p>
<p>A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote users to inject arbitrary web script or HTML via the Output code field in modules. The payload is executed when a user views or edits an article by adding slice that uses the compromised module.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vqc7-7fj4-3fm3"/>
  </entry>
</feed>
