<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:54:08 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-252386</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-252386</link>
      <description>EUVD-2026-252386</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-252386</guid>
    </item>
    <item>
      <title>fkie_cve-2025-58430</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58430</link>
      <description>&lt;p&gt;listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to the session cookie `session` there included `nonce`. The value is not checked and validated by the backend, removing `nonce` allows the requests to be processed correctly. This may seem harmless, but if chained to other vulnerabilities it can become a critical vulnerability. Cross-site request forgery and cross-site scripting chained together can result in improper admin account creation. As of time of publication, no patched versions are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to the session cookie `session` there included `nonce`. The value is not checked and validated by the backend, removing `nonce` allows the requests to be processed correctly. This may seem harmless, but if chained to other vulnerabilities it can become a critical vulnerability. Cross-site request forgery and cross-site scripting chained together can result in improper admin account creation. As of time of publication, no patched versions are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-58430</guid>
    </item>
    <item>
      <title>GHSA-rf24-wg77-gq7w — listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rf24-wg77-gq7w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/knadh/listmonk&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Cross-Site Request Forgery (CSRF) is an attack that forces an end user to execute unwanted actions on a web application in which they’re currently authenticated. With a little help of social engineering (such as sending a link via email or chat), an attacker may trick the users of a web application into executing actions of the attacker’s choosing. If the victim is a normal user, a successful CSRF attack can force the user to perform state changing requests like transferring funds, changing their email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;During a security evaluation of the webapp, every http request in addition to the session cookie `session` there included `nonce`. The value is not checked and validated by the backend, removing `nonce` allows the requests to be processed correctly.&lt;/p&gt;
&lt;p&gt;This may seem harmless, but if chained to other vulnerabilities it can become a critical vulnerability.&lt;/p&gt;
&lt;p&gt;Example HTTP request without nonce : 
&amp;lt;img width=&amp;#34;1418&amp;#34; height=&amp;#34;772&amp;#34; alt=&amp;#34;user_creation_without_nonce_burp_request&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/a5026cdd-d360-4919-ae66-29856c3d3f32&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s look at a “chain” case of vulnerabilities that include the CSRF and XSS.&lt;/p&gt;
&lt;p&gt;An admin (or any user with permissions) can create templates and preview them (`POST /api/templates/preview` ) making it possible to execute javascript code. For example:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1912&amp;#34; heigh…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/knadh/listmonk&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Cross-Site Request Forgery (CSRF) is an attack that forces an end user to execute unwanted actions on a web application in which they’re currently authenticated. With a little help of social engineering (such as sending a link via email or chat), an attacker may trick the users of a web application into executing actions of the attacker’s choosing. If the victim is a normal user, a successful CSRF attack can force the user to perform state changing requests like transferring funds, changing their email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;During a security evaluation of the webapp, every http request in addition to the session cookie `session` there included `nonce`. The value is not checked and validated by the backend, removing `nonce` allows the requests to be processed correctly.&lt;/p&gt;
&lt;p&gt;This may seem harmless, but if chained to other vulnerabilities it can become a critical vulnerability.&lt;/p&gt;
&lt;p&gt;Example HTTP request without nonce : 
&amp;lt;img width=&amp;#34;1418&amp;#34; height=&amp;#34;772&amp;#34; alt=&amp;#34;user_creation_without_nonce_burp_request&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/a5026cdd-d360-4919-ae66-29856c3d3f32&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s look at a “chain” case of vulnerabilities that include the CSRF and XSS.&lt;/p&gt;
&lt;p&gt;An admin (or any user with permissions) can create templates and preview them (`POST /api/templates/preview` ) making it possible to execute javascript code. For example:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1912&amp;#34; heigh…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rf24-wg77-gq7w</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15564-1 — govulncheck-vulndb-0.0.20250917T170349-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15564-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250917T170349-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250917T170349-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15564-1</guid>
    </item>
  </channel>
</rss>
