<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T09:54:52.003774+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-325925</id>
    <title>EUVD-2026-325925</title>
    <updated>2026-10-08T09:54:52.058885+00:00</updated>
    <content>EUVD-2026-325925</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-325925"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52778</id>
    <title>fkie_cve-2026-52778</title>
    <updated>2026-10-08T09:54:52.058942+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sanitize user-defined mathematical formulas using a complex recursive regular expression before passing them to the PHP eval() function. This implementation is inherently flawed: it is vulnerable to Regular Expression Denial of Service (ReDoS / Stack Overflow) which can crash the server, and it creates a high-risk architecture where any logic bypass directly results in arbitrary PHP code execution. Version 4.6.6 patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-52778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-px5m-h76g-p7p8</id>
    <title>GHSA-px5m-h76g-p7p8 — YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution &amp; Denial of Service</title>
    <updated>2026-10-08T09:54:52.058994+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: yeswiki/yeswiki</p>
<p>### Summary</p>
<p>An unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sanitize user-defined mathematical formulas using a complex recursive regular expression before passing them to the PHP eval() function. This implementation is inherently flawed: it is vulnerable to Regular Expression Denial of Service (ReDoS / Stack Overflow) which can crash the server, and it creates a high-risk architecture where any logic bypass directly results in arbitrary PHP code execution.</p>
<p>### Details</p>
<p>Affected Component
- **File**: tools/bazar/fields/CalcField.php
- **Method**: formatValuesBeforeSave($entry)
- **Vulnerable Mechanism:** Combination of a complex recursive regex validation followed by eval().</p>
<p>The code attempts to implement a sandbox for mathematical operations by verifying the formula structure before executing it:</p>
<p>```
$regexpToCheckIfMathFormula = '/^((' . $number . '|' . $functions . '\s*\((?1)+\)|\((?1)+\))(?:' . $operators . '(?1))?)+$/';</p>
<p>if (preg_match($regexpToCheckIfMathFormula, $formula)) {
    $formula = preg_replace('!pi|π!', 'pi()', $formula);
    try {
        eval("\$value = $formula;");  // VULNERABLE LINE
// ...
```
### Architectural Flaws</p>
<p>**PCRE Stack Overflow &amp; ReDoS (The Immediate Exploit):**</p>
<p>The regex definition heavily relies on a recursive pattern (?1)+. In PHP's PCRE engine, deeply nested recursive patterns are processed on the system stack. If an attacker inputs a formula with th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-px5m-h76g-p7p8"/>
  </entry>
</feed>
