<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T10:41:38.145524+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-328860</id>
    <title>EUVD-2026-328860</title>
    <updated>2026-10-08T10:41:38.147687+00:00</updated>
    <content>EUVD-2026-328860</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-328860"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56393</id>
    <title>fkie_cve-2026-56393</title>
    <updated>2026-10-08T10:41:38.147730+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Craft CMS 4.x (&gt;= 4.0.0-RC1, &lt; 4.17.0-beta.1) and 5.x (&gt;= 5.0.0-RC1, &lt; 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the checkbox.twig template, which used {{ label|raw }}). An authenticated administrator (with allowAdminChanges enabled) can inject malicious payloads into section names, volume names, user group names, global set names, generated field names, checkbox/radio option labels, and custom source labels, causing arbitrary JavaScript to execute in other users' control-panel sessions. Fixed in 4.17.0-beta.1 and 5.9.0-beta.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-56393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4mgv-366x-qxvx</id>
    <title>GHSA-4mgv-366x-qxvx — Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options</title>
    <updated>2026-10-08T10:41:38.147801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: craftcms/cms</p>
<p>## Overview of all XSS Reports</p>
<p>Multiple stored XSS vulnerabilities were found in Craft CMS. They were split into **4 reports** as follows:</p>
<p>| Report | What's Vulnerable | Why Separate |
|--------|-------------------|--------------|
| **This Report (1)** | Multiple settings names | Twig Template: `_includes/forms/checkbox.twig` |
| **Report 2** | Entry Types Name | Twig Template: `_includes/forms/editableTable.twig` |
| **Report 3** | Card Attributes in Field Layout | `helpers/Cp.php` |
| **Report 4 (Commerce)** | Product Type Name | Source in Commerce, sink in CMS - will report this one via Commerce GHSA |</p>
<p>Reports 2, 3, and 4 are clearly distinct locations. For this report (Report 1), it was not clear whether to split or consolidate these 7 bugs. The bug report was consolidated and the final categorization should be left to the judgement of the user.</p>
<p>**Note:** This overview is only in this Report. Other reports only reference this one.</p>
<p>---
## Summary</p>
<p>Stored XSS in multiple settings. Names/labels are rendered without sanitization via `checkbox.twig` template which uses `{{ label|raw }}`.</p>
<p>---
## Affected Sources</p>
<p>| #   | Source (injection point)                                                 | Sink (where payload reflects)                 |
| --- | ------------------------------------------------------------------------ | --------------------------------------------- |
| 1   | Section Name (`/admin/settings/sections`)                                | Entries field -&gt; So…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4mgv-366x-qxvx"/>
  </entry>
</feed>
