<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:57:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-207087</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-207087</link>
      <description>EUVD-2026-207087</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-207087</guid>
    </item>
    <item>
      <title>fkie_cve-2024-55879</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-55879</link>
      <description>&lt;p&gt;XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This has been patched in XWiki 15.10.9 and 16.3.0. No known workarounds are available except upgrading.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This has been patched in XWiki 15.10.9 and 16.3.0. No known workarounds are available except upgrading.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-55879</guid>
    </item>
    <item>
      <title>GHSA-r279-47wg-chpr — XWiki allows RCE from script right in configurable sections</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r279-47wg-chpr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xwiki.platform:xwiki-platform-administration-ui&lt;/p&gt;
&lt;p&gt;### Impact
Any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation.&lt;/p&gt;
&lt;p&gt;To reproduce on a instance, as a user with script rights, edit your user profile and add an object of type `XWiki.ConfigurableClass` (&amp;#34;Custom configurable sections&amp;#34;).
Set &amp;#34;Display in section&amp;#34; and &amp;#34;Display in category&amp;#34; to `other`, &amp;#34;Scope&amp;#34; to `Wiki and all spaces` and &amp;#34;Heading&amp;#34; to:
```
#set($codeToExecute = &amp;#39;Test&amp;#39;) #set($codeToExecuteResult = &amp;#39;{{async}}{{groovy}}services.logging.getLogger(&amp;#34;attacker&amp;#34;).error(&amp;#34;Attack from Heading succeeded!&amp;#34;){{/groovy}}{{/async}}&amp;#39;)
```
Save the page and view it, then add `?sheet=XWiki.AdminSheet&amp;amp;viewer=content&amp;amp;section=other` to the URL.
If the logs contain &amp;#34;attacker - Attack from Heading succeeded!&amp;#34;, then the instance is vulnerable.&lt;/p&gt;
&lt;p&gt;### Patches
This has been patched in XWiki 15.10.9 and 16.3.0.&lt;/p&gt;
&lt;p&gt;### Workarounds
We&amp;#39;re not aware of any workaround except upgrading.&lt;/p&gt;
&lt;p&gt;### References
* https://jira.xwiki.org/browse/XWIKI-21207
* https://github.com/xwiki/xwiki-platform/commit/8493435ff9606905a2d913607d6c79862d0c168d&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)
* Email us at [Security Mailing List](mailto:security@xwiki.org)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xwiki.platform:xwiki-platform-administration-ui&lt;/p&gt;
&lt;p&gt;### Impact
Any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation.&lt;/p&gt;
&lt;p&gt;To reproduce on a instance, as a user with script rights, edit your user profile and add an object of type `XWiki.ConfigurableClass` (&amp;#34;Custom configurable sections&amp;#34;).
Set &amp;#34;Display in section&amp;#34; and &amp;#34;Display in category&amp;#34; to `other`, &amp;#34;Scope&amp;#34; to `Wiki and all spaces` and &amp;#34;Heading&amp;#34; to:
```
#set($codeToExecute = &amp;#39;Test&amp;#39;) #set($codeToExecuteResult = &amp;#39;{{async}}{{groovy}}services.logging.getLogger(&amp;#34;attacker&amp;#34;).error(&amp;#34;Attack from Heading succeeded!&amp;#34;){{/groovy}}{{/async}}&amp;#39;)
```
Save the page and view it, then add `?sheet=XWiki.AdminSheet&amp;amp;viewer=content&amp;amp;section=other` to the URL.
If the logs contain &amp;#34;attacker - Attack from Heading succeeded!&amp;#34;, then the instance is vulnerable.&lt;/p&gt;
&lt;p&gt;### Patches
This has been patched in XWiki 15.10.9 and 16.3.0.&lt;/p&gt;
&lt;p&gt;### Workarounds
We&amp;#39;re not aware of any workaround except upgrading.&lt;/p&gt;
&lt;p&gt;### References
* https://jira.xwiki.org/browse/XWIKI-21207
* https://github.com/xwiki/xwiki-platform/commit/8493435ff9606905a2d913607d6c79862d0c168d&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)
* Email us at [Security Mailing List](mailto:security@xwiki.org)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r279-47wg-chpr</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3695 — xwiki: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3695</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in xwiki ausnutzen, um beliebigen Programmcode auszuführen oder Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in xwiki ausnutzen, um beliebigen Programmcode auszuführen oder Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3695</guid>
    </item>
  </channel>
</rss>
