<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 19:22:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-246033</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-246033</link>
      <description>EUVD-2026-246033</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-246033</guid>
    </item>
    <item>
      <title>fkie_cve-2025-53093</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-53093</link>
      <description>&lt;p&gt;TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version 3.1.1, any user can insert arbitrary HTMLinto the DOM by inserting a payload into any allowed attribute of the `&amp;lt;tabber&amp;gt;` tag. Version 3.1.1 contains a patch for the bug.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version 3.1.1, any user can insert arbitrary HTMLinto the DOM by inserting a payload into any allowed attribute of the `&amp;lt;tabber&amp;gt;` tag. Version 3.1.1 contains a patch for the bug.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-53093</guid>
    </item>
    <item>
      <title>GHSA-jfj7-249r-7j2m — TabberNeue vulnerable to Stored XSS through wikitext</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jfj7-249r-7j2m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: starcitizentools/tabber-neue&lt;/p&gt;
&lt;p&gt;### Summary
Arbitrary HTML can be inserted into the DOM by inserting a payload into any allowed attribute of the `&amp;lt;tabber&amp;gt;` tag.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `args` provided within the wikitext as attributes to the `&amp;lt;tabber&amp;gt;` tag are passed to the TabberComponentTabs class:
https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/blob/3a23b703ce36cfc4128e7921841f68230be4059a/includes/Tabber.php#L76&lt;/p&gt;
&lt;p&gt;In TabberComponentTabs, the attributes are validated before being supplied to the Tabs template.
https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/blob/3a23b703ce36cfc4128e7921841f68230be4059a/includes/Components/TabberComponentTabs.php#L15-L31
However, the validation is insufficient.
What `Sanitizer::validateTagAttributes` does is call `validateAttributes`, which
```
	 * - Discards attributes not on the given list
	 * - Unsafe style attributes are discarded
	 * - Invalid id attributes are re-encoded
```
However, the attribute values are expected to be escaped when inserted into HTML.&lt;/p&gt;
&lt;p&gt;The attribute values are then inserted into HTML without being escaped:
https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/blob/3a23b703ce36cfc4128e7921841f68230be4059a/includes/templates/Tabs.mustache#L1&lt;/p&gt;
&lt;p&gt;### PoC
#### XSS through attributes:
1. Go to Special:ExpandTemplates and insert the following wikitext:
```
&amp;lt;tabber class=&amp;#39;test123&amp;#34; onmouseenter=&amp;#34;alert(1)&amp;#34;&amp;#39;&amp;gt;
|-|First Tab Title=
First tab content goes here.
&amp;lt;/tabber&amp;gt;
```
2. Press &amp;#34;OK&amp;#34;
3. Hover over the tabber…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: starcitizentools/tabber-neue&lt;/p&gt;
&lt;p&gt;### Summary
Arbitrary HTML can be inserted into the DOM by inserting a payload into any allowed attribute of the `&amp;lt;tabber&amp;gt;` tag.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `args` provided within the wikitext as attributes to the `&amp;lt;tabber&amp;gt;` tag are passed to the TabberComponentTabs class:
https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/blob/3a23b703ce36cfc4128e7921841f68230be4059a/includes/Tabber.php#L76&lt;/p&gt;
&lt;p&gt;In TabberComponentTabs, the attributes are validated before being supplied to the Tabs template.
https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/blob/3a23b703ce36cfc4128e7921841f68230be4059a/includes/Components/TabberComponentTabs.php#L15-L31
However, the validation is insufficient.
What `Sanitizer::validateTagAttributes` does is call `validateAttributes`, which
```
	 * - Discards attributes not on the given list
	 * - Unsafe style attributes are discarded
	 * - Invalid id attributes are re-encoded
```
However, the attribute values are expected to be escaped when inserted into HTML.&lt;/p&gt;
&lt;p&gt;The attribute values are then inserted into HTML without being escaped:
https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/blob/3a23b703ce36cfc4128e7921841f68230be4059a/includes/templates/Tabs.mustache#L1&lt;/p&gt;
&lt;p&gt;### PoC
#### XSS through attributes:
1. Go to Special:ExpandTemplates and insert the following wikitext:
```
&amp;lt;tabber class=&amp;#39;test123&amp;#34; onmouseenter=&amp;#34;alert(1)&amp;#34;&amp;#39;&amp;gt;
|-|First Tab Title=
First tab content goes here.
&amp;lt;/tabber&amp;gt;
```
2. Press &amp;#34;OK&amp;#34;
3. Hover over the tabber…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jfj7-249r-7j2m</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1525 — MediaWiki Extensions und Skins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1525</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um SQL-Injection- und XSS-Angriffe durchzuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Informationen offenzulegen oder sich unbefugt höhere Berechtigungen zu verschaffen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um SQL-Injection- und XSS-Angriffe durchzuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Informationen offenzulegen oder sich unbefugt höhere Berechtigungen zu verschaffen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1525</guid>
    </item>
  </channel>
</rss>
