<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 12:30:47 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-211939</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-211939</link>
      <description>EUVD-2026-211939</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-211939</guid>
    </item>
    <item>
      <title>fkie_cve-2023-32070</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-32070</link>
      <description>&lt;p&gt;XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn&amp;#39;t check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known workarounds apart from upgrading to a fixed version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn&amp;#39;t check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known workarounds apart from upgrading to a fixed version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-32070</guid>
    </item>
    <item>
      <title>GHSA-6gf5-c898-7rxp — Improper Neutralization of Script in Attributes in XWiki (X)HTML renderers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6gf5-c898-7rxp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xwiki.rendering:xwiki-rendering-syntax-xhtml, Maven: org.xwiki.platform:xwiki-core-rendering-api, Maven: org.xwiki.rendering:xwiki-rendering-syntax-html, Maven: org.xwiki.rendering:xwiki-rendering-syntax-html5, Maven: org.xwiki.rendering:xwiki-rendering-syntax-annotatedxhtml, Maven: org.xwiki.rendering:xwiki-rendering-syntax-annotatedhtml5, Maven: org.xwiki.platform:xwiki-platform-annotation-core&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;HTML rendering didn&amp;#39;t check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax.&lt;/p&gt;
&lt;p&gt;### Patches
This has been patched in XWiki 14.6 RC1.&lt;/p&gt;
&lt;p&gt;### Workarounds
There are no known workarounds apart from upgrading to a fixed version.&lt;/p&gt;
&lt;p&gt;### References
* https://github.com/xwiki/xwiki-rendering/commit/c40e2f5f9482ec6c3e71dbf1fff5ba8a5e44cdc1
* https://jira.xwiki.org/browse/XRENDERING-663&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)
* Email us at [Security Mailing List](mailto:security@xwiki.org)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xwiki.rendering:xwiki-rendering-syntax-xhtml, Maven: org.xwiki.platform:xwiki-core-rendering-api, Maven: org.xwiki.rendering:xwiki-rendering-syntax-html, Maven: org.xwiki.rendering:xwiki-rendering-syntax-html5, Maven: org.xwiki.rendering:xwiki-rendering-syntax-annotatedxhtml, Maven: org.xwiki.rendering:xwiki-rendering-syntax-annotatedhtml5, Maven: org.xwiki.platform:xwiki-platform-annotation-core&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;HTML rendering didn&amp;#39;t check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax.&lt;/p&gt;
&lt;p&gt;### Patches
This has been patched in XWiki 14.6 RC1.&lt;/p&gt;
&lt;p&gt;### Workarounds
There are no known workarounds apart from upgrading to a fixed version.&lt;/p&gt;
&lt;p&gt;### References
* https://github.com/xwiki/xwiki-rendering/commit/c40e2f5f9482ec6c3e71dbf1fff5ba8a5e44cdc1
* https://jira.xwiki.org/browse/XRENDERING-663&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)
* Email us at [Security Mailing List](mailto:security@xwiki.org)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6gf5-c898-7rxp</guid>
    </item>
    <item>
      <title>gsd-2023-32070</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-32070</link>
      <description>gsd-2023-32070</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-32070</guid>
    </item>
  </channel>
</rss>
