<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:01:47 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0493 — De multiples vulnérabilités ont été découvertes dans les produits Centreon. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0493</link>
      <description>certfr-2025-avi-0493</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0493</guid>
    </item>
    <item>
      <title>EUVD-2026-258391</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258391</link>
      <description>EUVD-2026-258391</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258391</guid>
    </item>
    <item>
      <title>fkie_cve-2023-28447</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-28447</link>
      <description>&lt;p&gt;Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user&amp;#39;s browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application&amp;#39;s behavior, or unauthorized actions performed on behalf of the user. Users are advised to upgrade to either version 3.1.48 or to 4.3.1 to resolve this issue. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user&amp;#39;s browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application&amp;#39;s behavior, or unauthorized actions performed on behalf of the user. Users are advised to upgrade to either version 3.1.48 or to 4.3.1 to resolve this issue. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-28447</guid>
    </item>
    <item>
      <title>GHSA-7j98-h7fp-4vwj — smarty Cross-site Scripting vulnerability in Javascript escaping</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7j98-h7fp-4vwj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: smarty/smarty&lt;/p&gt;
&lt;p&gt;### Impact
An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user&amp;#39;s browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application&amp;#39;s behavior, or unauthorized actions performed on behalf of the user.&lt;/p&gt;
&lt;p&gt;### Patches
Please upgrade to the most recent version of Smarty v3 or v4.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory please open an issue in [the Smarty repo](https://github.com/smarty-php/smarty)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: smarty/smarty&lt;/p&gt;
&lt;p&gt;### Impact
An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user&amp;#39;s browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application&amp;#39;s behavior, or unauthorized actions performed on behalf of the user.&lt;/p&gt;
&lt;p&gt;### Patches
Please upgrade to the most recent version of Smarty v3 or v4.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory please open an issue in [the Smarty repo](https://github.com/smarty-php/smarty)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7j98-h7fp-4vwj</guid>
    </item>
    <item>
      <title>gsd-2023-28447</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-28447</link>
      <description>gsd-2023-28447</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-28447</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-28447</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28447</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: civicrm, Ubuntu:Pro:16.04:LTS: smarty3, Ubuntu:Pro:18.04:LTS: civicrm, Ubuntu:Pro:18.04:LTS: postfixadmin, Ubuntu:Pro:18.04:LTS: smarty3, Ubuntu:20.04:LTS: smarty3, Ubuntu:Pro:20.04:LTS: civicrm, Ubuntu:Pro:20.04:LTS: postfixadmin, Ubuntu:22.04:LTS: smarty3, Ubuntu:Pro:22.04:LTS: civicrm and 3 more&lt;/p&gt;
&lt;p&gt;Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user&amp;#39;s browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application&amp;#39;s behavior, or unauthorized actions performed on behalf of the user. Users are advised to upgrade to either version 3.1.48 or to 4.3.1 to resolve this issue. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: civicrm, Ubuntu:Pro:16.04:LTS: smarty3, Ubuntu:Pro:18.04:LTS: civicrm, Ubuntu:Pro:18.04:LTS: postfixadmin, Ubuntu:Pro:18.04:LTS: smarty3, Ubuntu:20.04:LTS: smarty3, Ubuntu:Pro:20.04:LTS: civicrm, Ubuntu:Pro:20.04:LTS: postfixadmin, Ubuntu:22.04:LTS: smarty3, Ubuntu:Pro:22.04:LTS: civicrm and 3 more&lt;/p&gt;
&lt;p&gt;Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user&amp;#39;s browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application&amp;#39;s behavior, or unauthorized actions performed on behalf of the user. Users are advised to upgrade to either version 3.1.48 or to 4.3.1 to resolve this issue. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28447</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0849 — MediaWiki: Mehrere Schwachstellen ermöglichen Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0849</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Cross-Site-Scripting-Angriff durchzuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Cross-Site-Scripting-Angriff durchzuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0849</guid>
    </item>
  </channel>
</rss>
