<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T12:02:57.733809+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318023</id>
    <title>EUVD-2026-318023</title>
    <updated>2026-10-06T12:02:57.802346+00:00</updated>
    <content>EUVD-2026-318023</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318023"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43939</id>
    <title>fkie_cve-2026-43939</title>
    <updated>2026-10-06T12:02:57.802383+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and later rendered back into the thread page without adequate HTML sanitization or contextual output encoding.  This vulnerability is fixed in 4.0.5 and 3.2.12.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43939"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8rq5-wwpp-fmj2</id>
    <title>GHSA-8rq5-wwpp-fmj2 — YAFNET has Stored XSS in Forum Thread Posts/Replies that Allows Arbitrary JavaScript Execution for All Thread Viewers</title>
    <updated>2026-10-06T12:02:57.802417+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: YAFNET.Core</p>
<p>**Description:**
Stored Cross-Site Scripting (XSS) occurs when user-supplied input is persisted by the application and later rendered in another user's browser without proper sanitization or contextual output encoding. When the vulnerable sink is a high-traffic surface such as a public forum thread, the payload executes in the browser of every user who visits the page, maximizing both reach and impact. Any JavaScript injected through such a sink runs under the application's origin and inherits the privileges of whichever user happens to view the affected content.</p>
<p>**Issue Details:**
The thread posting and reply feature accepts user-supplied content that is stored server-side and later rendered back into the thread page without adequate HTML sanitization or contextual output encoding. Submitting a post or reply containing `"&gt;&lt;img src=x onerror=prompt(0)&gt;` causes the payload to break out of the surrounding HTML context and inject a fully attacker-controlled `&lt;img&gt;` element whose `onerror` handler fires automatically as soon as the broken image reference fails to load. Because posts and replies are visible to every user who visits the thread, authenticated or otherwise, the injected JavaScript executes in each viewer's browser the moment the page renders, with no additional interaction required.</p>
<p>**Impact:**
An attacker with a standard forum account can execute arbitrary JavaScript in the browser of every user who loads the affected thread, including moderators and administrato…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8rq5-wwpp-fmj2"/>
  </entry>
</feed>
