<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T17:01:31.024828+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333259</id>
    <title>EUVD-2026-333259</title>
    <updated>2026-10-07T17:01:31.091784+00:00</updated>
    <content>EUVD-2026-333259</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-14794</id>
    <title>fkie_cve-2026-14794</title>
    <updated>2026-10-07T17:01:31.091824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData of the file src/controllers/ChartsController.php of the component Charts Endpoint. This manipulation of the argument userGroupId causes improper authorization. The attack is possible to be carried out remotely. Upgrading to version 4.18.1 addresses this issue. Patch name: 9ee53efc1314e6aba32771c66a13e072a246f4ce. It is suggested to upgrade the affected component.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-14794"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rvmm-v933-jgxq</id>
    <title>GHSA-rvmm-v933-jgxq — Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics</title>
    <updated>2026-10-07T17:01:31.091857+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: craftcms/cms</p>
<p>`ChartsController::actionGetNewUsersData()` at `/actions/charts/get-new-users-data` is missing a `requirePermission('viewUsers')` authorization check. Any authenticated control panel user, regardless of permissions beyond `accessCp`, can POST to this endpoint to receive time-series user registration counts for the entire site or for an arbitrary user group ID.</p>
<p>The `viewUsers` permission is consistently required throughout the control panel before exposing user-related data, but this action enforces only the base `accessCp` check inherited from the framework.</p>
<p>Each call returns the total count of users who joined the specified group in the requested period.</p>
<p>## Impact</p>
<p>Any control panel user with only `accessCp` permission can obtain the total number of registered users and their registration date distribution across any time window.</p>
<p>In installations with multiple editor roles, this allows a low-privilege control panel user to infer user group sizes and registration trends that would normally require the `viewUsers` permission to access.</p>
<p>No user PII (name, email, password) is disclosed; only aggregate counts and timestamps are returned. Confidentiality impact is low. No integrity or availability impact.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rvmm-v933-jgxq"/>
  </entry>
</feed>
