<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:15:32.301392+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-55630</id>
    <title>CVE-2026-55630 — Kiwi TCMS: Stored XSS via javascript: URI in extra_link field (TestPlan &amp; TestCase)</title>
    <updated>2026-10-02T14:15:32.303348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> kiwitcms Kiwi</p>
<p>Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS middleware send a Content-Security-Policy header that blocks inline JavaScript, making exploitation difficult in default deployments, while customized deployments that weaken those security settings may remain vulnerable. Version 16.1 properly sanitizes both fields and resets existing database records that do not validate to null. This issue is fixed in version 16.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-55630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-473p-56xx-vg67</id>
    <title>GHSA-473p-56xx-vg67 — Kiwi TCMS vulnerable to stored XSS via JavaScript: URI in extra_link field (TestPlan &amp; TestCase)</title>
    <updated>2026-10-02T14:15:32.303402+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: kiwitcms</p>
<p>## Summary</p>
<p>In Kiwi TCMS the fields `TestCase.extra_link` and `TestPlan.extra_link` were meant to represent URLs to external resources however in versions prior to 16.1 user input was not being sanitized and values were rendered verbatim which represents an opportunity for cross-site scripting exploitation. In version 16.1 these fields are properly sanitized and existing database records which don't validate will be reset to a null value.</p>
<p>## Impact</p>
<p>Deployments which use the official Docker images and/or unmodified Kiwi TCMS middleware send a `Content-Security-Policy` header which makes this vulnerability difficult to exploit in practice because this header blocks the browser from executing inline JavaScript. Customized deployments which modify the default security settings may still be vulnerable.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-473p-56xx-vg67"/>
  </entry>
</feed>
