<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T15:23:23.480567+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275715</id>
    <title>EUVD-2026-275715</title>
    <updated>2026-10-09T15:23:23.516113+00:00</updated>
    <content>EUVD-2026-275715</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275715"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31859</id>
    <title>fkie_cve-2026-31859</title>
    <updated>2026-10-09T15:23:23.516150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session. However, strip_tags() only removes HTML tags (angle brackets) -- it does not inspect or filter URL schemes. Payloads like javascript:alert(document.cookie) contain no HTML tags and pass through strip_tags() completely unmodified, enabling reflected XSS when the return URL is rendered in an href attribute. This vulnerability is fixed in  5.9.7 and 4.17.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-31859"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fvwq-45qv-xvhv</id>
    <title>GHSA-fvwq-45qv-xvhv — CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization</title>
    <updated>2026-10-09T15:23:23.516186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: craftcms/cms</p>
<p>### Summary</p>
<p>The fix for CVE-2025-35939 in `craftcms/cms` introduced a `strip_tags()` call in `src/web/User.php` to sanitize return URLs before they are stored in the session. However, `strip_tags()` only removes HTML tags (angle brackets) -- it does not inspect or filter URL schemes. Payloads like `javascript:alert(document.cookie)` contain no HTML tags and pass through `strip_tags()` completely unmodified, enabling reflected XSS when the return URL is rendered in an `href` attribute.</p>
<p>### Details
The patched code in is:</p>
<p>```php
public function setReturnUrl($url): void
{
    parent::setReturnUrl(strip_tags($url));
}
```</p>
<p>`strip_tags()` removes HTML tags (e.g., `&lt;script&gt;`, `&lt;img&gt;`) from a string, but it is **not** a URL sanitizer. When the sanitized return URL is subsequently rendered in an `href` attribute context (e.g., `&lt;a href="{{ returnUrl }}"&gt;`), the following dangerous payloads survive `strip_tags()` completely unmodified:</p>
<p>1. **`javascript:` protocol URLs** -- `javascript:alert(document.cookie)` contains no HTML tags, so `strip_tags()` returns it verbatim. When placed in an `href`, clicking the link executes the JavaScript.</p>
<p>2. **`data:` URIs** -- `data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==` uses Base64 encoding and contains no tags at all, bypassing `strip_tags()` entirely.</p>
<p>3. **Protocol-relative URLs** -- `//evil.com/steal` contains no tags and is passed through unchanged. When rendered as an `href`, the browser resolves it relative to the current…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fvwq-45qv-xvhv"/>
  </entry>
</feed>
