<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T20:44:31.755390+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-373275</id>
    <title>EUVD-2026-373275</title>
    <updated>2026-10-05T20:44:31.811540+00:00</updated>
    <content>EUVD-2026-373275</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-373275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63459</id>
    <title>fkie_cve-2026-63459</title>
    <updated>2026-10-05T20:44:31.811626+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrator-controlled description to a live element's innerHTML and then reading textContent. Active resource markup can execute an event handler during the innerHTML assignment before textContent is read. A lower-privilege administrator can store such markup in descriptions rendered by the Products list, Collections list, Promotions list, Payment Methods list, or Shipping Methods list, and script executes when another administrator views the affected row. This stored cross-site scripting can compromise the viewing administrator's session and enable cross-privilege or cross-channel administrative actions. This issue is fixed in version 3.6.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xhq9-whgq-49j5</id>
    <title>GHSA-xhq9-whgq-49j5 — Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions</title>
    <updated>2026-10-05T20:44:31.811668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @vendure/dashboard</p>
<p># Stored XSS in the Admin Dashboard via unsafe HTML-stripping (`innerHTML`) of entity descriptions</p>
<p>**Package:** @vendure/dashboard (vendure-ecommerce/vendure, latest master) ·</p>
<p>## Summary
The dashboard's `RichTextDescriptionCell` "strips HTML" from an entity's `description` by assigning it to a live element's `innerHTML` and reading back `textContent`. This pattern still **executes** active markup: a `description` containing `&lt;img src=x onerror=…&gt;` runs script when the element is parsed (image resource loads even on a detached node in Chromium/Firefox, firing `onerror`). Because `description` is an admin-settable field shown in multiple list views, a lower-privilege administrator can store a payload that executes in a **higher-privilege administrator's** browser when they open the corresponding list — stored XSS leading to admin-session compromise.</p>
<p>## Vulnerable code
`packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx`
```tsx
export const RichTextDescriptionCell: DataTableCellComponent&lt;{ description: string }&gt; = ({ cell }) =&gt; {
    const value = cell.getValue();
    const textContent = useMemo(() =&gt; {
        if (!value) return '';
        const div = document.createElement('div');
        div.innerHTML = value;          // line 51 — parses/loads active markup; &lt;img onerror&gt; fires here
        return div.textContent ?? '';   // line 52 — reading textContent does NOT undo the side effect
    }, [value]);
    ...
}
```
`innerHTML` does n…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xhq9-whgq-49j5"/>
  </entry>
</feed>
