<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:42:54 +0000</lastBuildDate>
    <item>
      <title>cnvd-2025-22701</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-22701</link>
      <description>cnvd-2025-22701</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-22701</guid>
    </item>
    <item>
      <title>EUVD-2026-245941</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-245941</link>
      <description>EUVD-2026-245941</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-245941</guid>
    </item>
    <item>
      <title>fkie_cve-2025-52902</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52902</link>
      <description>&lt;p&gt;File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of File Browser prior to v2.33.7 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser. Version 2.33.7 contains a fix for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of File Browser prior to v2.33.7 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser. Version 2.33.7 contains a fix for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-52902</guid>
    </item>
    <item>
      <title>GHSA-4wx8-5gm2-2j97 — filebrowser allows Stored Cross-Site Scripting through the Markdown preview function</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4wx8-5gm2-2j97</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser&lt;/p&gt;
&lt;p&gt;## Summary ##&lt;/p&gt;
&lt;p&gt;The Markdown preview function of File Browser v2.32.0 is vulnerable to *Stored Cross-Site-Scripting (XSS)*. Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser&lt;/p&gt;
&lt;p&gt;## Impact ##&lt;/p&gt;
&lt;p&gt;A user can upload a malicious Markdown file to the application which can contain arbitrary HTML code. If another user within the same scope clicks on that file, a rendered preview is opened. JavaScript code that has been included will be executed.&lt;/p&gt;
&lt;p&gt;Malicious actions that are possible include:
 
  * Obtaining a user&amp;#39;s session token
  * Elevating the attacker&amp;#39;s privileges, if the victim is an administrator (e.g., gaining command execution rights)&lt;/p&gt;
&lt;p&gt;## Vulnerability Description ##&lt;/p&gt;
&lt;p&gt;Most Markdown parsers accept arbitrary HTML in a document and try rendering it accordingly. For instance, if one creates a file called `xss.md` with the following content:&lt;/p&gt;
&lt;p&gt;```markdown
# Hallo&lt;/p&gt;
&lt;p&gt;&amp;lt;b&amp;gt;foo&amp;lt;/b&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;img src=&amp;#34;xx&amp;#34; onerror=alert(9)&amp;gt;
&amp;lt;i&amp;gt;bar&amp;lt;/i&amp;gt;
```&lt;/p&gt;
&lt;p&gt;Bold and italic text will be rendered. Also, the renderer used in File Browser will try to display the image and execute the code in the `onerror` event handler.&lt;/p&gt;
&lt;p&gt;## Proof of Concept ##&lt;/p&gt;
&lt;p&gt;The screenshot shows that the code from the file mentioned above has actually been executed in the victim&amp;#39;s browser:&lt;/p&gt;
&lt;p&gt;![JavaScript code being executed in the Markdown Preview](https://github.com/user-attachments/assets/3a3b9920-fbd8-433f-a016-ea77f5f68851)&lt;/p&gt;
&lt;p&gt;## Recommended Countermeasures ##&lt;/p&gt;
&lt;p&gt;The most thorough fix would be to reconf…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser&lt;/p&gt;
&lt;p&gt;## Summary ##&lt;/p&gt;
&lt;p&gt;The Markdown preview function of File Browser v2.32.0 is vulnerable to *Stored Cross-Site-Scripting (XSS)*. Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser&lt;/p&gt;
&lt;p&gt;## Impact ##&lt;/p&gt;
&lt;p&gt;A user can upload a malicious Markdown file to the application which can contain arbitrary HTML code. If another user within the same scope clicks on that file, a rendered preview is opened. JavaScript code that has been included will be executed.&lt;/p&gt;
&lt;p&gt;Malicious actions that are possible include:
 
  * Obtaining a user&amp;#39;s session token
  * Elevating the attacker&amp;#39;s privileges, if the victim is an administrator (e.g., gaining command execution rights)&lt;/p&gt;
&lt;p&gt;## Vulnerability Description ##&lt;/p&gt;
&lt;p&gt;Most Markdown parsers accept arbitrary HTML in a document and try rendering it accordingly. For instance, if one creates a file called `xss.md` with the following content:&lt;/p&gt;
&lt;p&gt;```markdown
# Hallo&lt;/p&gt;
&lt;p&gt;&amp;lt;b&amp;gt;foo&amp;lt;/b&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;img src=&amp;#34;xx&amp;#34; onerror=alert(9)&amp;gt;
&amp;lt;i&amp;gt;bar&amp;lt;/i&amp;gt;
```&lt;/p&gt;
&lt;p&gt;Bold and italic text will be rendered. Also, the renderer used in File Browser will try to display the image and execute the code in the `onerror` event handler.&lt;/p&gt;
&lt;p&gt;## Proof of Concept ##&lt;/p&gt;
&lt;p&gt;The screenshot shows that the code from the file mentioned above has actually been executed in the victim&amp;#39;s browser:&lt;/p&gt;
&lt;p&gt;![JavaScript code being executed in the Markdown Preview](https://github.com/user-attachments/assets/3a3b9920-fbd8-433f-a016-ea77f5f68851)&lt;/p&gt;
&lt;p&gt;## Recommended Countermeasures ##&lt;/p&gt;
&lt;p&gt;The most thorough fix would be to reconf…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4wx8-5gm2-2j97</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</guid>
    </item>
  </channel>
</rss>
