<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:42:22.989977+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-44990</id>
    <title>CVE-2026-44990 — Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`</title>
    <updated>2026-10-04T21:42:23.005764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> apostrophecms sanitize-html, Red Hat multicluster engine for Kubernetes 2.1, Red Hat multicluster engine for Kubernetes 2.11, Red Hat multicluster engine for Kubernetes 2.17, Red Hat multicluster engine for Kubernetes 2.6, Red Hat multicluster engine for Kubernetes 2.8, Red Hat multicluster engine for Kubernetes 2.9, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2.14 and 20 more</p>
<p>ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-44990"/>
  </entry>
</feed>
