<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 04:48:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-244207</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-244207</link>
      <description>EUVD-2026-244207</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-244207</guid>
    </item>
    <item>
      <title>fkie_cve-2025-49575</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49575</link>
      <description>&lt;p&gt;Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-49575</guid>
    </item>
    <item>
      <title>GHSA-4c2h-67qq-vm87 — Citizen skin vulnerable to stored XSS through multiple system messages</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4c2h-67qq-vm87</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: starcitizentools/citizen-skin&lt;/p&gt;
&lt;p&gt;### Summary
Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM.&lt;/p&gt;
&lt;p&gt;### Details
The messages are retrieved using the `plain()` output mode: https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/072e4365e9084e4b153eac62d3666566c06f5a49/resources/skins.citizen.commandPalette/components/CommandPaletteFooter.vue#L61-L66
`currentTip` is set to one of these messages: https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/072e4365e9084e4b153eac62d3666566c06f5a49/resources/skins.citizen.commandPalette/components/CommandPaletteFooter.vue#L69
`currentTip` is inserted as raw HTML (`vue/no-v-html` should *not* be ignored here): https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/072e4365e9084e4b153eac62d3666566c06f5a49/resources/skins.citizen.commandPalette/components/CommandPaletteFooter.vue#L3-L4&lt;/p&gt;
&lt;p&gt;### PoC
1. Edit `citizen-command-palette-tip-commands`, `citizen-command-palette-tip-users`, `citizen-command-palette-tip-namespace` and `citizen-command-palette-tip-templates` to `&amp;lt;img src=&amp;#34;&amp;#34; onerror=&amp;#34;alert(1)&amp;#34;&amp;gt;` (script tags don&amp;#39;t work here due to the way the HTML is inserted)
2. Open the command palette
![image](https://github.com/user-attachments/assets/f07b238b-1ac1-4781-8d03-db755ba04546)&lt;/p&gt;
&lt;p&gt;### Impact
This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: starcitizentools/citizen-skin&lt;/p&gt;
&lt;p&gt;### Summary
Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM.&lt;/p&gt;
&lt;p&gt;### Details
The messages are retrieved using the `plain()` output mode: https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/072e4365e9084e4b153eac62d3666566c06f5a49/resources/skins.citizen.commandPalette/components/CommandPaletteFooter.vue#L61-L66
`currentTip` is set to one of these messages: https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/072e4365e9084e4b153eac62d3666566c06f5a49/resources/skins.citizen.commandPalette/components/CommandPaletteFooter.vue#L69
`currentTip` is inserted as raw HTML (`vue/no-v-html` should *not* be ignored here): https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/072e4365e9084e4b153eac62d3666566c06f5a49/resources/skins.citizen.commandPalette/components/CommandPaletteFooter.vue#L3-L4&lt;/p&gt;
&lt;p&gt;### PoC
1. Edit `citizen-command-palette-tip-commands`, `citizen-command-palette-tip-users`, `citizen-command-palette-tip-namespace` and `citizen-command-palette-tip-templates` to `&amp;lt;img src=&amp;#34;&amp;#34; onerror=&amp;#34;alert(1)&amp;#34;&amp;gt;` (script tags don&amp;#39;t work here due to the way the HTML is inserted)
2. Open the command palette
![image](https://github.com/user-attachments/assets/f07b238b-1ac1-4781-8d03-db755ba04546)&lt;/p&gt;
&lt;p&gt;### Impact
This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4c2h-67qq-vm87</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1525 — MediaWiki Extensions und Skins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1525</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um SQL-Injection- und XSS-Angriffe durchzuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Informationen offenzulegen oder sich unbefugt höhere Berechtigungen zu verschaffen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um SQL-Injection- und XSS-Angriffe durchzuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Informationen offenzulegen oder sich unbefugt höhere Berechtigungen zu verschaffen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1525</guid>
    </item>
  </channel>
</rss>
