<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T07:16:21.827290+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-369648</id>
    <title>EUVD-2026-369648</title>
    <updated>2026-10-07T07:16:21.974886+00:00</updated>
    <content>EUVD-2026-369648</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-369648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55691</id>
    <title>fkie_cve-2026-55691</title>
    <updated>2026-10-07T07:16:21.974930+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the user-supplied class value directly to sprintf while constructing a figure element. A quote in the class value can terminate the class attribute and inject arbitrary HTML attributes or markup into the rendered page. A user able to edit a wiki page can store JavaScript that executes for visitors who render the affected content. This issue is fixed in version 4.1.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55691"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7h5p-637f-jfr7</id>
    <title>GHSA-7h5p-637f-jfr7 — StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template</title>
    <updated>2026-10-07T07:16:21.974970+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: starcitizenwiki/embedvideo</p>
<p>### Summary
The user supplied class value is fed directly into the sprintf call that creates HTML. You can add a quote to escape the class and then inject arbitrary html/javascript to the final output.</p>
<p>### Details
The template [here](https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/blob/a573a16d925ee0ea0d34b360856dc8ab0b88f822/includes/EmbedService/EmbedHtmlFormatter.php#L138) adds a figure with a class that is substituted in. This value is provided to sprintf [here](https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/blob/a573a16d925ee0ea0d34b360856dc8ab0b88f822/includes/EmbedService/EmbedHtmlFormatter.php#L156), an unescaped version of the class supplied by the user.</p>
<p>```
$template = &lt;&lt;&lt;HTML
    &lt;figure class="%s" data-service="%s" %s %s&gt;
        &lt;div class="embedvideo-wrapper" %s&gt;%s%s%s&lt;/div&gt;%s
    &lt;/figure&gt;
HTML;
```</p>
<p>### PoC
Note the double quote immediately following the single quote to escape the class attribute in the template:
```
&lt;youtube class='" onmouseover="alert(document.domain)' id="dQw4w9WgXcQ"&gt;dQw4w9WgXcQ&lt;/youtube&gt;
```</p>
<p>### Impact
Arbitrary HTML can be inserted into the DOM by any user on any page, allowing for JavaScript to be executed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7h5p-637f-jfr7"/>
  </entry>
</feed>
