<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T17:38:21.326477+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-374386</id>
    <title>EUVD-2026-374386</title>
    <updated>2026-10-06T17:38:21.359572+00:00</updated>
    <content>EUVD-2026-374386</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-374386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-76089</id>
    <title>fkie_cve-2026-76089</title>
    <updated>2026-10-06T17:38:21.359623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-76089"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9rg8-2wvr-fgjh</id>
    <title>GHSA-9rg8-2wvr-fgjh — Formie: Missing authorization on sent notification resend modal exposes submission PII</title>
    <updated>2026-10-06T17:38:21.359665+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: verbb/formie</p>
<p>### Impact</p>
<p>The control panel action `formie/sent-notifications/get-resend-modal-content` (`SentNotificationsController::actionGetResendModalContent`) performed only `requireAcceptsJson()` and loaded a `SentNotification` by request `id` without permission or object-level authorization checks.</p>
<p>Any authenticated user who could invoke the action could enumerate notification IDs and read full email content — including recipient headers and the complete HTML body containing submitted form data (PII) — without `formie-accessSentNotifications` or equivalent permission. Sibling actions in the same controller enforced authorization.</p>
<p>### Patches</p>
<p>Fixed in **3.1.31** (Craft 5) and **2.2.23** (Craft 4).</p>
<p>Craft 5: `canView()` is enforced after loading, consistent with `actionEdit`.  
Craft 4: `formie-viewSentNotifications` permission is required.</p>
<p>### Workarounds</p>
<p>Restrict CP access to trusted users only until upgraded. No configuration workaround.</p>
<p>- Reported by Jorge González (jorge@jmilla.es)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9rg8-2wvr-fgjh"/>
  </entry>
</feed>
