<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T23:21:05.457939+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-263473</id>
    <title>EUVD-2026-263473</title>
    <updated>2026-10-06T23:21:05.610871+00:00</updated>
    <content>EUVD-2026-263473</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-263473"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64781</id>
    <title>fkie_cve-2025-64781</title>
    <updated>2026-10-06T23:21:05.610927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1, "External page display restriction" is set to "Do not limit" in the initial configuration. With this configuration, the user may be redirected to an arbitrary website when accessing a specially crafted URL.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-64781"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-778m-x6m8-v6h8</id>
    <title>GHSA-778m-x6m8-v6h8</title>
    <updated>2026-10-06T23:21:05.610994+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1, "External page display restriction" is set to "Do not limit" in the initial configuration. With this configuration, the user may be redirected to an arbitrary website when accessing a specially crafted URL.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-778m-x6m8-v6h8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2025-000113</id>
    <title>jvndb-2025-000113</title>
    <updated>2026-10-06T23:21:05.611025+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GroupSession provided by Japan Total System Co.,Ltd. contains multiple vulnerabilities listed below.
&lt;ul&gt;&lt;li&gt;Stored cross-site scripting (CWE-79) - CVE-2025-53523&lt;/li&gt;
&lt;li&gt;Stored cross-site scripting (CWE-79) - CVE-2025-54407&lt;/li&gt;
&lt;li&gt;Reflected cross-site scripting (CWE-79) - CVE-2025-57883&lt;/li&gt;
&lt;li&gt;Cross-site request forgery (CWE-352) - CVE-2025-58576&lt;/li&gt;
&lt;li&gt;Authorization bypass through user-controlled key (CWE-639) - CVE-2025-61950&lt;/li&gt;
&lt;li&gt;Missing origin validation in webSockets (CWE-1385) - CVE-2025-61987&lt;/li&gt;&lt;li&gt;SQL injection (CWE-89) - CVE-2025-62192&lt;/li&gt;
&lt;li&gt;Initialization of a resource with an insecure default (CWE-1188) - CVE-2025-64781&lt;/li&gt;
&lt;li&gt;This can be exploited only when External page display restriction is set as "Do not limit", as in the initial configurationReflected cross-site scripting (CWE-79) - CVE-2025-65120&lt;/li&gt;
&lt;li&gt;Stored cross-site scripting (CWE-79) - CVE-2025-66284&lt;/li&gt;&lt;/ul&gt;
The following people reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2025-53523
Reporter: Shogo Iyota of GMO Cybersecurity by Ierae
        Gaku Mochizuki, Tsutomu Aramaki, and Taiga Shirakura of Mitsui Bussan Secure Directions, Inc.
        Natsumi Furukawa

CVE-2025-54407
Reporter: Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc.

CVE-2025-57883
Reporter: Tsuyuki Takumi of Mitsui Bussan Secure Directions, Inc.
        Ryo Sato

CVE-2025-58576
Rep…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2025-000113"/>
  </entry>
</feed>
