<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:04:56 +0000</lastBuildDate>
    <item>
      <title>certfr-2020-avi-465 — De multiples vulnérabilités ont été découvertes dans Zimbra. Elles
permettent à un attaquant de provoquer un problème d…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-465</link>
      <description>certfr-2020-avi-465</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-465</guid>
    </item>
    <item>
      <title>cnvd-2019-23289</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-23289</link>
      <description>cnvd-2019-23289</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-23289</guid>
    </item>
    <item>
      <title>EUVD-2026-60555</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-60555</link>
      <description>EUVD-2026-60555</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-60555</guid>
    </item>
    <item>
      <title>fkie_cve-2019-1010091</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-1010091</link>
      <description>&lt;p&gt;tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element&amp;#39;s embed tab.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element&amp;#39;s embed tab.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-1010091</guid>
    </item>
    <item>
      <title>GHSA-c78w-2gw7-gjv3 — XSS in TinyMCE</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c78w-2gw7-gjv3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: tinymce&lt;/p&gt;
&lt;p&gt;### Impact
A cross-site scripting (XSS) vulnerability was discovered in: the core parser and `media` plugin. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor via the clipboard or APIs. This impacts all users who are using TinyMCE 4.9.9 or lower and TinyMCE 5.2.1 or lower.&lt;/p&gt;
&lt;p&gt;### Patches
This vulnerability has been patched in TinyMCE 4.9.10 and 5.2.2 by improved HTML parsing and sanitization logic.&lt;/p&gt;
&lt;p&gt;### Workarounds
The workarounds available are:
- disable the media plugin and manually sanitize CDATA content (see below)
or
- upgrade to either TinyMCE 4.9.10 or TinyMCE 5.2.2&lt;/p&gt;
&lt;p&gt;#### Example: Manually strip CDATA elements
```js
setup: function(editor) {
  editor.on(&amp;#39;PreInit&amp;#39;, function() {
    editor.parser.addNodeFilter(&amp;#39;#cdata&amp;#39;, function(nodes) {
      for (var i = 0; i &amp;lt; nodes.length; i++) {
        nodes[i].remove();
      }
    });
  });
}
```&lt;/p&gt;
&lt;p&gt;### Acknowledgements
Tiny Technologies would like to thank Michał Bentkowski and [intivesec](https://github.com/intivesec) for discovering these vulnerabilities.&lt;/p&gt;
&lt;p&gt;### References
https://www.tiny.cloud/docs/release-notes/release-notes522/#securityfixes&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in the [TinyMCE repo](https://github.com/tinymce/tinymce/issues)
* Email us at [infosec@tiny.cloud](mailto:infosec@tiny.cloud)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: tinymce&lt;/p&gt;
&lt;p&gt;### Impact
A cross-site scripting (XSS) vulnerability was discovered in: the core parser and `media` plugin. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor via the clipboard or APIs. This impacts all users who are using TinyMCE 4.9.9 or lower and TinyMCE 5.2.1 or lower.&lt;/p&gt;
&lt;p&gt;### Patches
This vulnerability has been patched in TinyMCE 4.9.10 and 5.2.2 by improved HTML parsing and sanitization logic.&lt;/p&gt;
&lt;p&gt;### Workarounds
The workarounds available are:
- disable the media plugin and manually sanitize CDATA content (see below)
or
- upgrade to either TinyMCE 4.9.10 or TinyMCE 5.2.2&lt;/p&gt;
&lt;p&gt;#### Example: Manually strip CDATA elements
```js
setup: function(editor) {
  editor.on(&amp;#39;PreInit&amp;#39;, function() {
    editor.parser.addNodeFilter(&amp;#39;#cdata&amp;#39;, function(nodes) {
      for (var i = 0; i &amp;lt; nodes.length; i++) {
        nodes[i].remove();
      }
    });
  });
}
```&lt;/p&gt;
&lt;p&gt;### Acknowledgements
Tiny Technologies would like to thank Michał Bentkowski and [intivesec](https://github.com/intivesec) for discovering these vulnerabilities.&lt;/p&gt;
&lt;p&gt;### References
https://www.tiny.cloud/docs/release-notes/release-notes522/#securityfixes&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in the [TinyMCE repo](https://github.com/tinymce/tinymce/issues)
* Email us at [infosec@tiny.cloud](mailto:infosec@tiny.cloud)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c78w-2gw7-gjv3</guid>
    </item>
    <item>
      <title>gsd-2019-1010091</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-1010091</link>
      <description>gsd-2019-1010091</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-1010091</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-1010091</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-1010091</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: tinymce, Ubuntu:18.04:LTS: tinymce, Ubuntu:20.04:LTS: tinymce&lt;/p&gt;
&lt;p&gt;tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element&amp;#39;s embed tab.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: tinymce, Ubuntu:18.04:LTS: tinymce, Ubuntu:20.04:LTS: tinymce&lt;/p&gt;
&lt;p&gt;tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element&amp;#39;s embed tab.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-1010091</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0790 — IBM Maximo Asset Management: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0790</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Maximo Asset Management ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Maximo Asset Management ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0790</guid>
    </item>
  </channel>
</rss>
