<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 21:06:49 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-209811</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-209811</link>
      <description>EUVD-2026-209811</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-209811</guid>
    </item>
    <item>
      <title>fkie_cve-2023-23913</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-23913</link>
      <description>&lt;p&gt;There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-23913</guid>
    </item>
    <item>
      <title>GHSA-xp5h-f8jf-rc8q — rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xp5h-f8jf-rc8q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: actionview&lt;/p&gt;
&lt;p&gt;NOTE: rails-ujs is part of Rails/actionview since 5.1.0.&lt;/p&gt;
&lt;p&gt;There is a potential DOM based cross-site scripting issue in rails-ujs
which leverages the Clipboard API to target HTML elements that are
assigned the contenteditable attribute. This has the potential to
occur when pasting malicious HTML content from the clipboard that
includes a data-method, data-remote or data-disable-with attribute.&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned the CVE identifier CVE-2023-23913.&lt;/p&gt;
&lt;p&gt;Not affected: &amp;lt; 5.1.0
Versions Affected: &amp;gt;= 5.1.0
Fixed Versions: 6.1.7.3, 7.0.4.3&lt;/p&gt;
&lt;p&gt;Impact
  If the specified malicious HTML clipboard content is provided to a
  contenteditable element, this could result in the arbitrary execution
  of javascript on the origin in question.&lt;/p&gt;
&lt;p&gt;Releases
  The FIXED releases are available at the normal locations.&lt;/p&gt;
&lt;p&gt;Workarounds
  We recommend that all users upgrade to one of the FIXED versions.
  In the meantime, users can attempt to mitigate this vulnerability
  by removing the contenteditable attribute from elements in pages
  that rails-ujs will interact with.&lt;/p&gt;
&lt;p&gt;Patches
  To aid users who aren’t able to upgrade immediately we have provided
  patches for the two supported release series. They are in git-am
  format and consist of a single changeset.&lt;/p&gt;
&lt;p&gt;* rails-ujs-data-method-contenteditable-6-1.patch - Patch for 6.1 series
* rails-ujs-data-method-contenteditable-7-0.patch - Patch for 7.0 series&lt;/p&gt;
&lt;p&gt;Please note that only the 7.0.Z and 6.1.Z series are
supported at present, and 6.0.Z for sev…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: actionview&lt;/p&gt;
&lt;p&gt;NOTE: rails-ujs is part of Rails/actionview since 5.1.0.&lt;/p&gt;
&lt;p&gt;There is a potential DOM based cross-site scripting issue in rails-ujs
which leverages the Clipboard API to target HTML elements that are
assigned the contenteditable attribute. This has the potential to
occur when pasting malicious HTML content from the clipboard that
includes a data-method, data-remote or data-disable-with attribute.&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned the CVE identifier CVE-2023-23913.&lt;/p&gt;
&lt;p&gt;Not affected: &amp;lt; 5.1.0
Versions Affected: &amp;gt;= 5.1.0
Fixed Versions: 6.1.7.3, 7.0.4.3&lt;/p&gt;
&lt;p&gt;Impact
  If the specified malicious HTML clipboard content is provided to a
  contenteditable element, this could result in the arbitrary execution
  of javascript on the origin in question.&lt;/p&gt;
&lt;p&gt;Releases
  The FIXED releases are available at the normal locations.&lt;/p&gt;
&lt;p&gt;Workarounds
  We recommend that all users upgrade to one of the FIXED versions.
  In the meantime, users can attempt to mitigate this vulnerability
  by removing the contenteditable attribute from elements in pages
  that rails-ujs will interact with.&lt;/p&gt;
&lt;p&gt;Patches
  To aid users who aren’t able to upgrade immediately we have provided
  patches for the two supported release series. They are in git-am
  format and consist of a single changeset.&lt;/p&gt;
&lt;p&gt;* rails-ujs-data-method-contenteditable-6-1.patch - Patch for 6.1 series
* rails-ujs-data-method-contenteditable-7-0.patch - Patch for 7.0 series&lt;/p&gt;
&lt;p&gt;Please note that only the 7.0.Z and 6.1.Z series are
supported at present, and 6.0.Z for sev…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xp5h-f8jf-rc8q</guid>
    </item>
    <item>
      <title>gsd-2023-23913</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-23913</link>
      <description>gsd-2023-23913</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-23913</guid>
    </item>
    <item>
      <title>OESA-2024-1774 — rubygem-actionview security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1774</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: rubygem-actionview&lt;/p&gt;
&lt;p&gt;Simple, battle-tested conventions and helpers for building web pages.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in Rails. rails-ujs may allow an attacker to perform Cross-Site Scripting (XSS), which could lead to stolen information, phishing attacks, and other types of attacks.(CVE-2023-23913)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: rubygem-actionview&lt;/p&gt;
&lt;p&gt;Simple, battle-tested conventions and helpers for building web pages.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in Rails. rails-ujs may allow an attacker to perform Cross-Site Scripting (XSS), which could lead to stolen information, phishing attacks, and other types of attacks.(CVE-2023-23913)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1774</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:3813-1 — Security update for rubygem-actionview-5_1</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:3813-1</link>
      <description>&lt;p&gt;Security update for rubygem-actionview-5_1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rubygem-actionview-5_1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:3813-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-23913</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-23913</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails&lt;/p&gt;
&lt;p&gt;There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails&lt;/p&gt;
&lt;p&gt;There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-23913</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0632 — Ruby on Rails: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0632</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, unbekannte Auswirkungen zu verursachen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, unbekannte Auswirkungen zu verursachen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0632</guid>
    </item>
  </channel>
</rss>
