<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T04:43:56.534718+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322440</id>
    <title>EUVD-2026-322440</title>
    <updated>2026-10-10T04:43:56.537133+00:00</updated>
    <content>EUVD-2026-322440</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322440"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46367</id>
    <title>fkie_cve-2026-46367</title>
    <updated>2026-10-10T04:43:56.537167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticated users to inject JavaScript via malformed URLs in comments. Attackers can craft URLs with unescaped quotes to inject event handlers, stealing admin session cookies and achieving full application takeover when visitors view affected FAQ pages.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9525-27vj-c8r8</id>
    <title>GHSA-9525-27vj-c8r8 — phpMyFAQ has stored XSS via Utils::parseUrl() in comment rendering</title>
    <updated>2026-10-10T04:43:56.537200+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq</p>
<p>### Summary</p>
<p>A stored XSS vulnerability in the comment rendering pipeline allows an authenticated user to inject JavaScript that executes for every visitor of an affected FAQ or News page. An attacker with a registered account can steal admin session cookies and take over the application.</p>
<p>### Details</p>
<p>`Utils::parseUrl()` (`phpmyfaq/src/phpMyFAQ/Utils.php`, line 281) converts URLs in comment text into clickable `&lt;a&gt;` tags at render time:</p>
<p>$pattern = '/(https?:\/\/[^\s]+)/i';
    $replacement = '&lt;a href="$1"&gt;$1&lt;/a&gt;';
    return preg_replace($pattern, $replacement, $string);</p>
<p>The regex `[^\s]+` matches `"` and `&lt;`, and the URL is inserted into the href attribute with no htmlspecialchars() call. A URL with a literal `"` closes the attribute early and allows injecting event handlers like onmouseover.</p>
<p>This only reaches the sink when `main.enableCommentEditor` is enabled. In that path, comment text goes through `sanitizeHtmlComment()` instead of `FILTER_SANITIZE_SPECIAL_CHARS` — which encodes `"` — so the double-quote survives to storage. The comment is then passed through parseUrl() and rendered via `{{ comment.comment|raw }}` in `comment.macros.twig` (line 40), which disables Twig auto-escaping.</p>
<p>The same sink exists in the admin comment panel (`admin/content/comments.twig`, lines 62 and 112), so admins viewing the panel are also affected.</p>
<p>No Content-Security-Policy headers are set anywhere in the app.</p>
<p>### PoC</p>
<p>Requirements:
- main.enableCommentEditor = true (set in admin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9525-27vj-c8r8"/>
  </entry>
</feed>
