<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:49:14 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-244208</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-244208</link>
      <description>EUVD-2026-244208</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-244208</guid>
    </item>
    <item>
      <title>fkie_cve-2025-49577</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49577</link>
      <description>&lt;p&gt;Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-49577</guid>
    </item>
    <item>
      <title>GHSA-jwr7-992g-68mh — starcitizentools/citizen-skin allows stored XSS in preference menu heading messages</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jwr7-992g-68mh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: starcitizentools/citizen-skin&lt;/p&gt;
&lt;p&gt;### Summary
Various preferences messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM.&lt;/p&gt;
&lt;p&gt;### Details
The `innerHtml` of the label div is set to the `textContent` of the label, essentially unsanitizing the system messages:
https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/407052e7069bdeae927d6f1a2a1c9a45b473bf9a/resources/skins.citizen.preferences/addPortlet.polyfill.js#L18&lt;/p&gt;
&lt;p&gt;### PoC
1. Edit `citizen-feature-custom-font-size-name` (or any other message displayed in a heading in the preferences menu) to `&amp;lt;img src=&amp;#34;&amp;#34; onerror=&amp;#34;alert(&amp;#39;citizen-feature-custom-font-size-name&amp;#39;)&amp;#34;&amp;gt;` (script tags don&amp;#39;t work here due to the way the HTML is inserted)
2. Open the preferences menu
![image](https://github.com/user-attachments/assets/b75f100d-09cc-443c-b635-e9d6ab48d133)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: starcitizentools/citizen-skin&lt;/p&gt;
&lt;p&gt;### Summary
Various preferences messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM.&lt;/p&gt;
&lt;p&gt;### Details
The `innerHtml` of the label div is set to the `textContent` of the label, essentially unsanitizing the system messages:
https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/407052e7069bdeae927d6f1a2a1c9a45b473bf9a/resources/skins.citizen.preferences/addPortlet.polyfill.js#L18&lt;/p&gt;
&lt;p&gt;### PoC
1. Edit `citizen-feature-custom-font-size-name` (or any other message displayed in a heading in the preferences menu) to `&amp;lt;img src=&amp;#34;&amp;#34; onerror=&amp;#34;alert(&amp;#39;citizen-feature-custom-font-size-name&amp;#39;)&amp;#34;&amp;gt;` (script tags don&amp;#39;t work here due to the way the HTML is inserted)
2. Open the preferences menu
![image](https://github.com/user-attachments/assets/b75f100d-09cc-443c-b635-e9d6ab48d133)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jwr7-992g-68mh</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1525 — MediaWiki Extensions und Skins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1525</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um SQL-Injection- und XSS-Angriffe durchzuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Informationen offenzulegen oder sich unbefugt höhere Berechtigungen zu verschaffen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um SQL-Injection- und XSS-Angriffe durchzuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Informationen offenzulegen oder sich unbefugt höhere Berechtigungen zu verschaffen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1525</guid>
    </item>
  </channel>
</rss>
