<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T21:08:09.581697+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-372383</id>
    <title>EUVD-2026-372383</title>
    <updated>2026-10-05T21:08:09.583956+00:00</updated>
    <content>EUVD-2026-372383</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-372383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-77607</id>
    <title>fkie_cve-2026-77607</title>
    <updated>2026-10-05T21:08:09.583989+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` was inserted verbatim into HTML cell joins. This made it possible to inject HTML through the separator value. Version 7.2.0 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-77607"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7xv3-gf2g-498h</id>
    <title>GHSA-7xv3-gf2g-498h — Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS</title>
    <updated>2026-10-05T21:08:09.584021+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: mediawiki/semantic-media-wiki</p>
<p>#### Failure mode</p>
<p>`sep` was inserted verbatim into the HTML that joins a table cell's values. This made it possible to inject HTML through the separator value. The same unsanitised table HTML is produced both for the standard `Special:Ask` render and for its raw request output (`request_type=raw`), so the injection was reachable without authentication.</p>
<p>#### Remediation</p>
<p>- In all non-wiki output modes (HTML, raw request, file), `sep` is escaped unless it is a safe `&lt;br&gt;` variant.
- This preserves legitimate line-break separators while blocking markup injection.</p>
<p>#### Maintenance note</p>
<p>If the table renderer ever gains richer separator semantics, keep the whitelist explicit. Do not expand the allowed HTML surface casually.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7xv3-gf2g-498h"/>
  </entry>
</feed>
