<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T18:09:15.794229+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-263437</id>
    <title>EUVD-2026-263437</title>
    <updated>2026-10-06T18:09:15.872666+00:00</updated>
    <content>EUVD-2026-263437</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-263437"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66284</id>
    <title>fkie_cve-2025-66284</title>
    <updated>2026-10-06T18:09:15.872724+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-66284"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gvxm-fhfx-8g6r</id>
    <title>GHSA-gvxm-fhfx-8g6r</title>
    <updated>2026-10-06T18:09:15.872774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gvxm-fhfx-8g6r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2025-000113</id>
    <title>jvndb-2025-000113</title>
    <updated>2026-10-06T18:09:15.872802+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GroupSession provided by Japan Total System Co.,Ltd. contains multiple vulnerabilities listed below.
&lt;ul&gt;&lt;li&gt;Stored cross-site scripting (CWE-79) - CVE-2025-53523&lt;/li&gt;
&lt;li&gt;Stored cross-site scripting (CWE-79) - CVE-2025-54407&lt;/li&gt;
&lt;li&gt;Reflected cross-site scripting (CWE-79) - CVE-2025-57883&lt;/li&gt;
&lt;li&gt;Cross-site request forgery (CWE-352) - CVE-2025-58576&lt;/li&gt;
&lt;li&gt;Authorization bypass through user-controlled key (CWE-639) - CVE-2025-61950&lt;/li&gt;
&lt;li&gt;Missing origin validation in webSockets (CWE-1385) - CVE-2025-61987&lt;/li&gt;&lt;li&gt;SQL injection (CWE-89) - CVE-2025-62192&lt;/li&gt;
&lt;li&gt;Initialization of a resource with an insecure default (CWE-1188) - CVE-2025-64781&lt;/li&gt;
&lt;li&gt;This can be exploited only when External page display restriction is set as "Do not limit", as in the initial configurationReflected cross-site scripting (CWE-79) - CVE-2025-65120&lt;/li&gt;
&lt;li&gt;Stored cross-site scripting (CWE-79) - CVE-2025-66284&lt;/li&gt;&lt;/ul&gt;
The following people reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2025-53523
Reporter: Shogo Iyota of GMO Cybersecurity by Ierae
        Gaku Mochizuki, Tsutomu Aramaki, and Taiga Shirakura of Mitsui Bussan Secure Directions, Inc.
        Natsumi Furukawa

CVE-2025-54407
Reporter: Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc.

CVE-2025-57883
Reporter: Tsuyuki Takumi of Mitsui Bussan Secure Directions, Inc.
        Ryo Sato

CVE-2025-58576
Rep…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2025-000113"/>
  </entry>
</feed>
