<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:34:16.266679+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-267143</id>
    <title>EUVD-2026-267143</title>
    <updated>2026-10-06T16:34:16.315244+00:00</updated>
    <content>EUVD-2026-267143</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-267143"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23476</id>
    <title>fkie_cve-2026-23476</title>
    <updated>2026-10-06T16:34:16.315284+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected XSS bug in FacturaScripts. The problem is in how error messages get displayed. Twig's | raw filter is used, which skips HTML escaping. When triggering a database error (like passing a string where an integer is expected), the error message includes the input and gets rendered without sanitization. This vulnerability is fixed in 2025.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g6w2-q45f-xrp4</id>
    <title>GHSA-g6w2-q45f-xrp4 — FacturaScripts is Vulnerable to Reflected XSS</title>
    <updated>2026-10-06T16:34:16.315319+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: facturascripts/facturascripts</p>
<p># Reflected XSS via SQL Error Messages</p>
<p>## Summary</p>
<p>A reflected XSS bug has been found in FacturaScripts. The problem is in how error messages get displayed - it's using Twig's `| raw` filter which skips HTML escaping. When a database error is triggered (like passing a string where an integer is expected), the error message includes all input and gets rendered without sanitization.</p>
<p>Attackers can use this to phish credentials from other users since HttpOnly is set on cookies (so stealing cookies directly won't work, but attackers can inject a fake login form).</p>
<p>**CVSS 6.1 (Medium-High)**</p>
<p>---</p>
<p>## What was Found</p>
<p>### Where the bug exists in the code:</p>
<p>`Core/View/Macro/Utils.html.twig`, line 27:</p>
<p>```twig
{% for item in messages %}
    &lt;div&gt;{{ item.message | raw }}&lt;/div&gt;
{% endfor %}
```</p>
<p>That `| raw` is the problem. It tells Twig not to escape anything.</p>
<p>### How it works</p>
<p>So here's what happens:</p>
<p>1. Hhit `/EditProducto?code=&lt;svg onload=alert(1)&gt; or &lt;img src=x onerror=alert(1)&gt;`
2. The app tries to look up a product with that "code"
3. PostgreSQL throws an error because `&lt;svg onload=alert(1)&gt;` isn't a valid integer
4. The error goes something like:   ```
   ERROR: invalid input syntax for type integer: "&lt;svg onload=alert(1)&gt;"
   LINE 1: SELECT * FROM "productos" WHERE "idproducto" = '&lt;img src=x onerror=alert(1)&gt;"
   ```
5. This gets logged via MiniLog and displayed to the user
6. Because of `| raw`, the browser actually executes the JS</p>
<p>The error logging happens in `Core/Base/D…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g6w2-q45f-xrp4"/>
  </entry>
</feed>
