<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 13:33:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-232511</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232511</link>
      <description>EUVD-2026-232511</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232511</guid>
    </item>
    <item>
      <title>fkie_cve-2022-41928</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41928</link>
      <description>&lt;p&gt;XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code (&amp;#39;Eval Injection&amp;#39;) in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` macro properties. This has been patched in versions 13.10.7, 14.4.2, and 14.5. The issue can be fixed on a running wiki by updating `XWiki.AttachmentSelector` with the versions below: - 14.5-rc-1+: https://github.com/xwiki/xwiki-platform/commit/eb15147adf94bddb92626f862c1710d45bcd64a7#diff-e1513599ab698991f6cbba55d38f3f464432ced8d137a668b1f7618c7e747e23 - 14.4.2+: https://github.com/xwiki/xwiki-platform/commit/c02f8eb1f3c953d124f2c097021536f8bc00fa8d#diff-e1513599ab698991f6cbba55d38f3f464432ced8d137a668b1f7618c7e747e23 - 13.10.7+: https://github.com/xwiki/xwiki-platform/commit/efd0df0468d46149ba68b66660b93f31b6318515#diff-e1513599ab698991f6cbba55d38f3f464432ced8d137a668b1f7618c7e747e23&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code (&amp;#39;Eval Injection&amp;#39;) in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` macro properties. This has been patched in versions 13.10.7, 14.4.2, and 14.5. The issue can be fixed on a running wiki by updating `XWiki.AttachmentSelector` with the versions below: - 14.5-rc-1+: https://github.com/xwiki/xwiki-platform/commit/eb15147adf94bddb92626f862c1710d45bcd64a7#diff-e1513599ab698991f6cbba55d38f3f464432ced8d137a668b1f7618c7e747e23 - 14.4.2+: https://github.com/xwiki/xwiki-platform/commit/c02f8eb1f3c953d124f2c097021536f8bc00fa8d#diff-e1513599ab698991f6cbba55d38f3f464432ced8d137a668b1f7618c7e747e23 - 13.10.7+: https://github.com/xwiki/xwiki-platform/commit/efd0df0468d46149ba68b66660b93f31b6318515#diff-e1513599ab698991f6cbba55d38f3f464432ced8d137a668b1f7618c7e747e23&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-41928</guid>
    </item>
    <item>
      <title>GHSA-9hqh-fmhg-vq2j — Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9hqh-fmhg-vq2j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xwiki.platform:xwiki-platform-attachment-ui&lt;/p&gt;
&lt;p&gt;### Impact
Any user with the right to edit his personal page can follow one of the scenario below:&lt;/p&gt;
&lt;p&gt;**Scenario 1**:
- Log in as a simple user with just edit rights on the user profile
- Go to the user&amp;#39;s profile
- Upload an attachment in the attachment tab at the bottom of the page (any image is fine)
- Click on &amp;#34;rename&amp;#34; in the attachment list and enter `{{async async=&amp;#34;true&amp;#34; cached=&amp;#34;false&amp;#34; context=&amp;#34;doc.reference&amp;#34;}}{{groovy}}println(&amp;#34;Hello from groovy!&amp;#34;){{/groovy}}{{/async}}.png` as new attachment name and submit the rename
- Go back to the user profile
- Click on the edit icon on the user avatar
- `Hello from groovy!` is displayed as the title of the attachment&lt;/p&gt;
&lt;p&gt;**Scenario 2**:
- Log in as a simple user with just edit rights on a page
- Create a Page `MyPage.WebHome`
- Create an XClass field of type String named `avatar`
- Add an XObject of type `MyPage.WebHome` on the page
- Insert an `attachmentSelector` macro in the document with the following values:
  - **classname**: `MyPage.WebHome`
  - **property**: `avatar`
  - **savemode**: `direct`
  - **displayImage**: `true`
  - **width**: `]] {{async async=&amp;#34;true&amp;#34; cached=&amp;#34;false&amp;#34; context=&amp;#34;doc.reference&amp;#34;}}{{groovy}}println(&amp;#34;Hello from groovy!&amp;#34;){{/groovy}}{{/async}}`. You&amp;#39;ll find below a snippet of an `attachmentSelector` macro declaration.
- Display the page
- Use the attachment picker to select an image
- `Hello from groovy` is displayed aside the image&lt;/p&gt;
&lt;p&gt;Example of an `attachmentSelector` macro declaration:
```
`{{attachmentSelect…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xwiki.platform:xwiki-platform-attachment-ui&lt;/p&gt;
&lt;p&gt;### Impact
Any user with the right to edit his personal page can follow one of the scenario below:&lt;/p&gt;
&lt;p&gt;**Scenario 1**:
- Log in as a simple user with just edit rights on the user profile
- Go to the user&amp;#39;s profile
- Upload an attachment in the attachment tab at the bottom of the page (any image is fine)
- Click on &amp;#34;rename&amp;#34; in the attachment list and enter `{{async async=&amp;#34;true&amp;#34; cached=&amp;#34;false&amp;#34; context=&amp;#34;doc.reference&amp;#34;}}{{groovy}}println(&amp;#34;Hello from groovy!&amp;#34;){{/groovy}}{{/async}}.png` as new attachment name and submit the rename
- Go back to the user profile
- Click on the edit icon on the user avatar
- `Hello from groovy!` is displayed as the title of the attachment&lt;/p&gt;
&lt;p&gt;**Scenario 2**:
- Log in as a simple user with just edit rights on a page
- Create a Page `MyPage.WebHome`
- Create an XClass field of type String named `avatar`
- Add an XObject of type `MyPage.WebHome` on the page
- Insert an `attachmentSelector` macro in the document with the following values:
  - **classname**: `MyPage.WebHome`
  - **property**: `avatar`
  - **savemode**: `direct`
  - **displayImage**: `true`
  - **width**: `]] {{async async=&amp;#34;true&amp;#34; cached=&amp;#34;false&amp;#34; context=&amp;#34;doc.reference&amp;#34;}}{{groovy}}println(&amp;#34;Hello from groovy!&amp;#34;){{/groovy}}{{/async}}`. You&amp;#39;ll find below a snippet of an `attachmentSelector` macro declaration.
- Display the page
- Use the attachment picker to select an image
- `Hello from groovy` is displayed aside the image&lt;/p&gt;
&lt;p&gt;Example of an `attachmentSelector` macro declaration:
```
`{{attachmentSelect…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9hqh-fmhg-vq2j</guid>
    </item>
    <item>
      <title>gsd-2022-41928</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-41928</link>
      <description>gsd-2022-41928</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-41928</guid>
    </item>
  </channel>
</rss>
