<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T15:12:46.109475+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335580</id>
    <title>EUVD-2026-335580</title>
    <updated>2026-10-06T15:12:46.114547+00:00</updated>
    <content>EUVD-2026-335580</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335580"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49276</id>
    <title>fkie_cve-2026-49276</title>
    <updated>2026-10-06T15:12:46.114599+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any blueprint allowed a scripting link to be included as the target of a link or email link in writer mark components, making the target clickable by the user who entered it and enabling self cross-site scripting in the Panel. This issue is fixed in versions 4.9.4 and 5.4.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-49276"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rhj6-r49h-5932</id>
    <title>GHSA-rhj6-r49h-5932 — Kirby: Self cross-site scripting (self-XSS) in the writer field</title>
    <updated>2026-10-06T15:12:46.114632+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: getkirby/cms</p>
<p>### TL;DR</p>
<p>This vulnerability affects Kirby sites that use the writer field in any blueprint.</p>
<p>It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it.</p>
<p>A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack *cannot* be automated.</p>
<p>In Kirby's default configuration, the vulnerability is limited to self-XSS and *cannot* directly affect other users or visitors of the site. Panel plugins that are directly using the `&lt;k-writer&gt;` component may also be affected by stored XSS if they don't sanitize the resulting HTML before saving it to the content.</p>
<p>**This vulnerability is of high severity for affected sites.**</p>
<p>----</p>
<p>### Introduction</p>
<p>Cross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim.</p>
<p>*Self* cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields.</p>
<p>In a *stored* XSS attack, the malic…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rhj6-r49h-5932"/>
  </entry>
</feed>
