<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:45:32 +0000</lastBuildDate>
    <item>
      <title>fkie_cve-2025-2901</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-2901</link>
      <description>&lt;p&gt;Rejected reason: This vulnerability is redundant to CVE-2025-23366 and CVE-2024-10234.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rejected reason: This vulnerability is redundant to CVE-2025-23366 and CVE-2024-10234.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-2901</guid>
    </item>
    <item>
      <title>GHSA-f7jh-m6wp-jm7f — HAL Cross Site Scripting (XSS) vulnerability of user input when storing it in a data store</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f7jh-m6wp-jm7f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jboss.hal:hal-console&lt;/p&gt;
&lt;p&gt;A flaw was found in the JBoss EAP Management Console, where a stored Cross-site scripting vulnerability occurs when an application improperly sanitizes user input before storing it in a data store. When this stored data is later included in web pages without adequate sanitization, malicious scripts can execute in the context of users who view these pages, leading to potential data theft, session hijacking, or other malicious activities.&lt;/p&gt;
&lt;p&gt;### Impact
Cross-site scripting (XSS) vulnerability in the management console.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in [HAL 3.7.11.Final](https://github.com/hal/console/releases/tag/v3.7.11)&lt;/p&gt;
&lt;p&gt;### Workarounds
No workaround available&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jboss.hal:hal-console&lt;/p&gt;
&lt;p&gt;A flaw was found in the JBoss EAP Management Console, where a stored Cross-site scripting vulnerability occurs when an application improperly sanitizes user input before storing it in a data store. When this stored data is later included in web pages without adequate sanitization, malicious scripts can execute in the context of users who view these pages, leading to potential data theft, session hijacking, or other malicious activities.&lt;/p&gt;
&lt;p&gt;### Impact
Cross-site scripting (XSS) vulnerability in the management console.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in [HAL 3.7.11.Final](https://github.com/hal/console/releases/tag/v3.7.11)&lt;/p&gt;
&lt;p&gt;### Workarounds
No workaround available&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f7jh-m6wp-jm7f</guid>
    </item>
    <item>
      <title>RHSA-2025:10452 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.0.8 Security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:10452</link>
      <description>&lt;p&gt;org.jboss.eap:wildfly-ejb3: Improper Deserialization in JBoss Marshalling Allows Remote Code Execution org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console org.apache.cxf: Apache CXF: Denial of Service vulnerability with temporary files base-x: base-x homograph attack allows Unicode lookalike characters to bypass validation. commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;org.jboss.eap:wildfly-ejb3: Improper Deserialization in JBoss Marshalling Allows Remote Code Execution org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console org.apache.cxf: Apache CXF: Denial of Service vulnerability with temporary files base-x: base-x homograph attack allows Unicode lookalike characters to bypass validation. commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:10452</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0650 — Red Hat JBoss Enterprise Application Platform: Schwachstelle ermöglicht Cross-Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0650</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat JBoss Enterprise Application Platform ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat JBoss Enterprise Application Platform ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0650</guid>
    </item>
  </channel>
</rss>
