<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T14:17:43.783124+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322433</id>
    <title>EUVD-2026-322433</title>
    <updated>2026-10-05T14:17:43.834605+00:00</updated>
    <content>EUVD-2026-322433</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322433"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46360</id>
    <title>fkie_cve-2026-46360</title>
    <updated>2026-10-05T14:17:43.834659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass sanitization. Authenticated users with FAQ_EDIT permission can upload malicious SVG files with deeply nested ampersand encoding around numeric HTML entities to reconstruct javascript: URLs, which execute arbitrary JavaScript when clicked by other users viewing the uploaded SVG.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46360"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-whqh-9pq5-c7r3</id>
    <title>GHSA-whqh-9pq5-c7r3 — phpMyFAQ has a SVG Sanitizer Entity Decoding Depth Limit Bypass Leading to Stored XSS</title>
    <updated>2026-10-05T14:17:43.834697+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: phpmyfaq/phpmyfaq, Packagist: thorsten/phpmyfaq</p>
<p>## Summary</p>
<p>The `SvgSanitizer::decodeAllEntities()` method limits recursive entity decoding to 5 iterations. By wrapping each character of `javascript` in an `href` attribute value with 5 levels of `&amp;amp;` encoding around numeric HTML entities (e.g., `&amp;amp;amp;amp;amp;amp;#106;` for `j`), an attacker can bypass both `isSafe()` detection and `sanitize()` removal. The uploaded SVG is served from the application origin with `image/svg+xml` content type, and the browser's XML parser fully decodes the remaining `&amp;#NNN;` entities, resulting in a clickable `javascript:` link that executes arbitrary JavaScript.</p>
<p>## Details</p>
<p>**Root cause:** `decodeAllEntities()` at `phpmyfaq/src/phpMyFAQ/Helper/SvgSanitizer.php:223-249` limits entity decoding to `maxIterations=5`. Each iteration: (1) decodes `&amp;#NNN;` numeric entities, (2) decodes `&amp;#xHH;` hex entities, (3) calls `html_entity_decode()` which resolves one level of `&amp;amp;` → `&amp;`. With 5 levels of `&amp;amp;` wrapping, all 5 iterations are consumed unwinding the `&amp;amp;` nesting, leaving the final `&amp;#NNN;` numeric entities unresolved.</p>
<p>**Code path:**</p>
<p>1. Authenticated user with `FAQ_EDIT` permission uploads SVG via `POST /admin/api/content/images` (`ImageController::upload()` at line 39)
2. File extension is `svg` → `SvgSanitizer::isSafe()` called (line 114)
3. `isSafe()` calls `decodeAllEntities()` — 5 iterations resolve `&amp;amp;` nesting but leave `&amp;#106;&amp;#97;...` (numeric entities for `javascript`)
4. Pattern matching at line 47 (`/href\s*=\…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-whqh-9pq5-c7r3"/>
  </entry>
</feed>
