<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T08:55:21.308991+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-354932</id>
    <title>EUVD-2026-354932</title>
    <updated>2026-10-09T08:55:21.359953+00:00</updated>
    <content>EUVD-2026-354932</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-354932"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-75828</id>
    <title>fkie_cve-2026-75828</title>
    <updated>2026-10-09T08:55:21.360001+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like onerror= that pass validation and execute in visitor browsers when page content is rendered.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-75828"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vfmf-q6x9-cw96</id>
    <title>GHSA-vfmf-q6x9-cw96 — Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stor…</title>
    <updated>2026-10-09T08:55:21.360038+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: getgrav/grav</p>
<p>## Affected versions and vulnerable location</p>
<p>- Confirmed on grav core at `78ebfc1` (tag 2.0.13).
- Detector: `system/src/Grav/Common/Security.php:290`, the `on_events` regex, run via `patternMatches()` (`:315-330`).
- The `on_events` pattern at HEAD:
  `#&lt;(?:"[^"]*"|'[^']*'|[^&gt;"'])*?(?:[\s\x00-\x20"'/]|"[^"]*"|'[^']*')on\s*[a-z]+\s*=#iu`
- Sole save-time guard for non-super content: `Validation::checkSafety()` (`system/src/Grav/Common/Data/Validation.php:160` scalars, `:165` arrays), invoked per field from `BlueprintSchema::validate` -&gt; `Validation::checkSafety` (`system/src/Grav/Common/Data/BlueprintSchema.php:248`). `security.xss_whitelist: [admin.super]` exempts only super-admins (`Validation.php:148`).</p>
<p>## Root cause (distinct from GHSA-269c)</p>
<p>GHSA-269c hardened the tag-body scan to be quote-aware so a `&gt;` inside a paired quoted attribute value is treated as data, not a tag close. That same quote-awareness opened a new gap: the regex treats ANY `"` or `'` as a string delimiter, but HTML only enters a quoted-value state when a quote appears immediately after `=`. A single unpaired quote sitting inside an unquoted attribute value is, to the browser, just a value character; to the regex it is an unterminated string that neither `[^&gt;"']` nor `"[^"]*"` can consume, so the lazy tag-body scan cannot advance past it to reach the following ` on...=` handler. No alignment matches and `detectXss()` returns null.</p>
<p>## Proof (executed)</p>
<p>The detector was replicated verbatim (the `on_e…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vfmf-q6x9-cw96"/>
  </entry>
</feed>
