<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:58:34.854990+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-320166</id>
    <title>EUVD-2026-320166</title>
    <updated>2026-10-04T09:58:34.902853+00:00</updated>
    <content>EUVD-2026-320166</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-320166"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40596</id>
    <title>fkie_cve-2026-40596</title>
    <updated>2026-10-04T09:58:34.902892+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated user to inject arbitrary HTML by updating their account's font family. Upon exploitation, an XSS payload would be reflected on every MantisBT page. Leveraging another vulnerability (CSP bypass, see GHSA-9c3j-xm6v-j7j3), the attacker could achieve account takeover. This issue has been fixed in version 2.28.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40596"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j3v9-553h-x28j</id>
    <title>GHSA-j3v9-553h-x28j — MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preference</title>
    <updated>2026-10-04T09:58:34.902927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: mantisbt/mantisbt</p>
<p>Any authenticated user can inject arbitrary HTML via updating their account's font family.</p>
<p>### Impact
Cross-site scripting.
The injected payload will be reflected in every MantisBT page.</p>
<p>Leveraging another vulnerability (CSP bypass, see [GHSA-9c3j-xm6v-j7j3](https://github.com/mantisbt/mantisbt/security/advisories/GHSA-9c3j-xm6v-j7j3)), the attacker could achieve account takeover.</p>
<p>### Patches
- 9e8409cdd979eba86ef532756fc47c1d8112d22d</p>
<p>### Workarounds
None</p>
<p>### Credits
Thanks to siunam (Tang Cheuk Hei) for discovering and responsibly reporting the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j3v9-553h-x28j"/>
  </entry>
</feed>
