<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T16:36:00.702699+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338427</id>
    <title>EUVD-2026-338427</title>
    <updated>2026-10-09T16:36:00.704837+00:00</updated>
    <content>EUVD-2026-338427</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44175</id>
    <title>fkie_cve-2026-44175</title>
    <updated>2026-10-09T16:36:00.704870+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list field on save, leaving it vulnerable to cross-site scripting (XSS). Kirby's list field stores its formatted content as HTML, and unlike other field types, its HTML special characters cannot be escaped without losing the formatting. Sanitization was only enforced client-side in the Panel, while the server did not sanitize the content on save. As a result, an attacker could bypass the Panel and send malicious HTML directly to Kirby's API, storing unsanitized markup in the content file. That markup would then be rendered on the site frontend and executed in the browsers of site visitors and logged-in users browsing the site, resulting in persistent XSS. This issue has been fixed in versions 4.9.1 and 5.4.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44175"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5fhx-9q32-q257</id>
    <title>GHSA-5fhx-9q32-q257 — Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend</title>
    <updated>2026-10-09T16:36:00.704906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: getkirby/cms</p>
<p>### TL;DR</p>
<p>This vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block.</p>
<p>**This vulnerability is of high severity for affected sites.**</p>
<p>Kirby sites are *not* affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content.</p>
<p>----</p>
<p>### Introduction</p>
<p>Cross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim.</p>
<p>In a *stored* XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors.</p>
<p>Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible.</p>
<p>A specific class of stored XSS is auto-fir…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5fhx-9q32-q257"/>
  </entry>
</feed>
