<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 01:11:15 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-14927</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14927</link>
      <description>bdu:2025-14927</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14927</guid>
    </item>
    <item>
      <title>EUVD-2026-261950</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261950</link>
      <description>EUVD-2026-261950</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261950</guid>
    </item>
    <item>
      <title>fkie_cve-2025-21621</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21621</link>
      <description>&lt;p&gt;GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a reflected cross-site scripting (XSS) vulnerability exists in the WMS GetFeatureInfo HTML output format that enables a remote attacker to execute arbitrary JavaScript code in a victim&amp;#39;s browser through specially crafted SLD_BODY parameters. This issue has been patched in version 2.25.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a reflected cross-site scripting (XSS) vulnerability exists in the WMS GetFeatureInfo HTML output format that enables a remote attacker to execute arbitrary JavaScript code in a victim&amp;#39;s browser through specially crafted SLD_BODY parameters. This issue has been patched in version 2.25.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-21621</guid>
    </item>
    <item>
      <title>GHSA-w66h-j855-qr72 — GeoServer has a Reflected Cross-Site Scripting (XSS) vulnerability in its WMS GetFeatureInfo HTML format</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w66h-j855-qr72</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.geoserver.web:gs-web-app, Maven: org.geoserver:gs-wms&lt;/p&gt;
&lt;p&gt;### Summary
A reflected cross-site scripting (XSS) vulnerability exists in the WMS GetFeatureInfo HTML output format that enables a remote attacker to execute arbitrary JavaScript code in a victim&amp;#39;s browser through specially crafted SLD_BODY parameters.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The WMS service setting that controls HTML auto-escaping is either disabled by default, or completely missing, in the affected versions (see workarounds).&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If an attacker can control a script that is executed in the victim&amp;#39;s browser, then they can typically fully compromise that user. Amongst other things, the attacker can:
1. Perform any action within the application that the user can perform.
2. View any information that the user is able to view.
3. Modify any information that the user is able to modify.
4. Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.&lt;/p&gt;
&lt;p&gt;### Workarounds
Changing any of the following WMS service settings should mitigate this vulnerability in most environments:
1. Enable GetFeatureInfo HTML auto-escaping (available in GeoServer 2.21.3+ and 2.22.1+)
2. Disable dynamic styling
3. Disable GetFeatureInfo text/html MIME type&lt;/p&gt;
&lt;p&gt;### References
https://osgeo-org.atlassian.net/browse/GEOS-11297
https://github.com/geoserver/geoserver/pull/7406&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.geoserver.web:gs-web-app, Maven: org.geoserver:gs-wms&lt;/p&gt;
&lt;p&gt;### Summary
A reflected cross-site scripting (XSS) vulnerability exists in the WMS GetFeatureInfo HTML output format that enables a remote attacker to execute arbitrary JavaScript code in a victim&amp;#39;s browser through specially crafted SLD_BODY parameters.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The WMS service setting that controls HTML auto-escaping is either disabled by default, or completely missing, in the affected versions (see workarounds).&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If an attacker can control a script that is executed in the victim&amp;#39;s browser, then they can typically fully compromise that user. Amongst other things, the attacker can:
1. Perform any action within the application that the user can perform.
2. View any information that the user is able to view.
3. Modify any information that the user is able to modify.
4. Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.&lt;/p&gt;
&lt;p&gt;### Workarounds
Changing any of the following WMS service settings should mitigate this vulnerability in most environments:
1. Enable GetFeatureInfo HTML auto-escaping (available in GeoServer 2.21.3+ and 2.22.1+)
2. Disable dynamic styling
3. Disable GetFeatureInfo text/html MIME type&lt;/p&gt;
&lt;p&gt;### References
https://osgeo-org.atlassian.net/browse/GEOS-11297
https://github.com/geoserver/geoserver/pull/7406&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w66h-j855-qr72</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2676 — GeoServer: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2676</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in GeoServer ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um Informationen offenzulegen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in GeoServer ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um Informationen offenzulegen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2676</guid>
    </item>
  </channel>
</rss>
