<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T00:25:12.827542+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-264987</id>
    <title>EUVD-2026-264987</title>
    <updated>2026-10-08T00:25:12.829874+00:00</updated>
    <content>EUVD-2026-264987</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-264987"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68455</id>
    <title>fkie_cve-2025-68455</title>
    <updated>2026-10-08T00:25:12.829906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have administrator access to the Craft Control Panel for this to work. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68455"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-255j-qw47-wjh5</id>
    <title>GHSA-255j-qw47-wjh5 — Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior</title>
    <updated>2026-10-08T00:25:12.829937+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: craftcms/cms</p>
<p>Note that attackers must have administrator access to the Craft Control Panel for this to work.</p>
<p>Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.</p>
<p>Resources:</p>
<p>https://github.com/craftcms/cms/commit/6e608a1a5bfb36943f94f584b7548ca542a86fef</p>
<p>https://github.com/craftcms/cms/commit/27f55886098b56c00ddc53b69239c9c9192252c7</p>
<p>https://github.com/craftcms/cms/commit/ec43c497edde0b2bf2e39a119cded2e55f9fe593</p>
<p>https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5821---2025-12-04</p>
<p>### Summary</p>
<p>This was reported as a vulnerability in Yii framework on August 7th (https://github.com/yiisoft/yii2/security/advisories/GHSA-gcmh-9pjj-7fp4). The Yii framework team denies responsibility for this (placing the onus on application developers) and hence has not (and seemingly will not) provide a fix at the framework level. Hence, I am reporting this to Craft as I found it to affect the latest (`5.6.0`) version of Craft CMS.</p>
<p>Leveraging a legitimate but maliciously crafted Yii `Behavior` class, it’s possible to trigger Remote Code Execution (RCE) via Reflection when the tainted `Behavior` is attached to a Yii `Component`, and an event is also fired on the tainted `Component`.</p>
<p>### Details
This vulnerability is inspired by `CVE-2024-4990` but differs because a legitimate Yii `Behavior` class is used to abuse the magic `__set()` and `__get()` methods to trigger an arbitrary PHP callable, ultimately leading to RCE. As such, this bypasses the mitigations implemente…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-255j-qw47-wjh5"/>
  </entry>
</feed>
