<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:48:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-244211</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-244211</link>
      <description>EUVD-2026-244211</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-244211</guid>
    </item>
    <item>
      <title>fkie_cve-2025-49578</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49578</link>
      <description>&lt;p&gt;Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right. This vulnerability is fixed in 3.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-49578</guid>
    </item>
    <item>
      <title>GHSA-2v3v-3whp-953h — starcitizentools/citizen-skin allows stored XSS in user registration date message</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2v3v-3whp-953h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: starcitizentools/citizen-skin&lt;/p&gt;
&lt;p&gt;### Summary
Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM.&lt;/p&gt;
&lt;p&gt;### Details
The result of `$this-&amp;gt;lang-&amp;gt;userDate( $timestamp, $this-&amp;gt;user )` returns unescaped values, but is inserted as raw HTML by Citizen:
https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/072e4365e9084e4b153eac62d3666566c06f5a49/includes/Components/CitizenComponentUserInfo.php#L55-L60&lt;/p&gt;
&lt;p&gt;### PoC
1. Go to any page using citizen with the uselang parameter set to x-xss and while being logged in
Depending on the registration date of the account you&amp;#39;re logged in with, various messages can be shown. In my case, it&amp;#39;s `november`:
![image](https://github.com/user-attachments/assets/252a3453-99c8-4ce1-b6d6-a8485b7a9a43)&lt;/p&gt;
&lt;p&gt;### Impact
This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: starcitizentools/citizen-skin&lt;/p&gt;
&lt;p&gt;### Summary
Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM.&lt;/p&gt;
&lt;p&gt;### Details
The result of `$this-&amp;gt;lang-&amp;gt;userDate( $timestamp, $this-&amp;gt;user )` returns unescaped values, but is inserted as raw HTML by Citizen:
https://github.com/StarCitizenTools/mediawiki-skins-Citizen/blob/072e4365e9084e4b153eac62d3666566c06f5a49/includes/Components/CitizenComponentUserInfo.php#L55-L60&lt;/p&gt;
&lt;p&gt;### PoC
1. Go to any page using citizen with the uselang parameter set to x-xss and while being logged in
Depending on the registration date of the account you&amp;#39;re logged in with, various messages can be shown. In my case, it&amp;#39;s `november`:
![image](https://github.com/user-attachments/assets/252a3453-99c8-4ce1-b6d6-a8485b7a9a43)&lt;/p&gt;
&lt;p&gt;### Impact
This impacts wikis where a group has the `editinterface` but not the `editsitejs` user right.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2v3v-3whp-953h</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1525 — MediaWiki Extensions und Skins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1525</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um SQL-Injection- und XSS-Angriffe durchzuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Informationen offenzulegen oder sich unbefugt höhere Berechtigungen zu verschaffen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um SQL-Injection- und XSS-Angriffe durchzuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Informationen offenzulegen oder sich unbefugt höhere Berechtigungen zu verschaffen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1525</guid>
    </item>
  </channel>
</rss>
