<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:29:53 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-248729</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248729</link>
      <description>EUVD-2026-248729</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248729</guid>
    </item>
    <item>
      <title>fkie_cve-2025-47943</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-47943</link>
      <description>&lt;p&gt;Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-site scripting (XSS) vulnerability present in Gogs, which allows client-side Javascript code execution. The vulnerability is caused by the usage of a vulnerable and outdated component: pdfjs-1.4.20 under public/plugins/. This issue has been fixed for gogs.io/gogs in version 0.13.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-site scripting (XSS) vulnerability present in Gogs, which allows client-side Javascript code execution. The vulnerability is caused by the usage of a vulnerable and outdated component: pdfjs-1.4.20 under public/plugins/. This issue has been fixed for gogs.io/gogs in version 0.13.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-47943</guid>
    </item>
    <item>
      <title>GHSA-xh32-cx6c-cp4v — Gogs XSS allowed by stored call in PDF renderer</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xh32-cx6c-cp4v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gogs/gogs, Go: gogs.io/gogs&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A stored XSS is present in Gogs which allows client-side Javascript code execution.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Gogs Version:
```
docker images
REPOSITORY   TAG       IMAGE ID       CREATED        SIZE
gogs/gogs    latest    fe92583bc4fe   10 hours ago   99.3MB
```&lt;/p&gt;
&lt;p&gt;Application version: `0.14.0+dev`&lt;/p&gt;
&lt;p&gt;Local setup using:
```bash
# Pull image from Docker Hub.
docker pull gogs/gogs&lt;/p&gt;
&lt;p&gt;# Create local directory for volume.
sudo mkdir -p /var/gogs&lt;/p&gt;
&lt;p&gt;# Use `docker run` for the first time.
docker run --name=gogs -p 10022:22 -p 10880:3000 -v /var/gogs:/data gogs/gogs
```&lt;/p&gt;
&lt;p&gt;The vulnerability is caused by the usage of a vulnerable and outdated component: `pdfjs-1.4.20` under public/plugins/.  
Read more about this vulnerability at [codeanlabs - CVE-2024-4367](https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js/).&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Upload the Proof of Concept file hosted at https://codeanlabs.com/wp-content/uploads/2024/05/poc_generalized_CVE-2024-4367.pdf in a repository.
2. Click on the file to be previewed.&lt;/p&gt;
&lt;p&gt;![poc](https://github.com/user-attachments/assets/5af1303e-8751-49c8-af2e-d0631dd18957)&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;Edoardo Ottavianelli&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gogs/gogs, Go: gogs.io/gogs&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A stored XSS is present in Gogs which allows client-side Javascript code execution.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Gogs Version:
```
docker images
REPOSITORY   TAG       IMAGE ID       CREATED        SIZE
gogs/gogs    latest    fe92583bc4fe   10 hours ago   99.3MB
```&lt;/p&gt;
&lt;p&gt;Application version: `0.14.0+dev`&lt;/p&gt;
&lt;p&gt;Local setup using:
```bash
# Pull image from Docker Hub.
docker pull gogs/gogs&lt;/p&gt;
&lt;p&gt;# Create local directory for volume.
sudo mkdir -p /var/gogs&lt;/p&gt;
&lt;p&gt;# Use `docker run` for the first time.
docker run --name=gogs -p 10022:22 -p 10880:3000 -v /var/gogs:/data gogs/gogs
```&lt;/p&gt;
&lt;p&gt;The vulnerability is caused by the usage of a vulnerable and outdated component: `pdfjs-1.4.20` under public/plugins/.  
Read more about this vulnerability at [codeanlabs - CVE-2024-4367](https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js/).&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Upload the Proof of Concept file hosted at https://codeanlabs.com/wp-content/uploads/2024/05/poc_generalized_CVE-2024-4367.pdf in a repository.
2. Click on the file to be previewed.&lt;/p&gt;
&lt;p&gt;![poc](https://github.com/user-attachments/assets/5af1303e-8751-49c8-af2e-d0631dd18957)&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;Edoardo Ottavianelli&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xh32-cx6c-cp4v</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1383 — Gogs: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1383</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gogs ausnutzen, um beliebigen Programmcode auszuführen, und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gogs ausnutzen, um beliebigen Programmcode auszuführen, und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1383</guid>
    </item>
  </channel>
</rss>
