<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T16:59:08.885135+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-59332</id>
    <title>CVE-2025-59332 — 3DAlloy allows stored XSS through attributes provided to the 3d parser tag/function</title>
    <updated>2026-10-07T16:59:08.901801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> dolfinus 3DAlloy</p>
<p>3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the &lt;3d&gt; parser tag and the {{#3d}} parser function allow users to provide custom attributes that are then appended to the canvas HTML element that is being output by the extension. The attributes are not sanitized, which means that arbitrary JavaScript can be inserted and executed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-59332"/>
  </entry>
</feed>
