<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:48:52 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-253447</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-253447</link>
      <description>EUVD-2026-253447</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-253447</guid>
    </item>
    <item>
      <title>fkie_cve-2025-59839</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59839</link>
      <description>&lt;p&gt;The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext. This issue has been patched via commit 4e075d3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext. This issue has been patched via commit 4e075d3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-59839</guid>
    </item>
    <item>
      <title>GHSA-4j5h-mvj3-m48v — Star Citizen  EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4j5h-mvj3-m48v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: starcitizenwiki/embedvideo&lt;/p&gt;
&lt;p&gt;### Summary
The EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The attributes of an iframe are populated with the value of an unreserved data attribute (`data-iframeconfig`) that can be set via wikitext:
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/blob/440fb331a84b2050f4cc084c1d31d58a1d1c202d/resources/ext.embedVideo.videolink.js#L5-L20
Similar code is also present here:
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/blob/440fb331a84b2050f4cc084c1d31d58a1d1c202d/resources/modules/iframe.js#L139-L155&lt;/p&gt;
&lt;p&gt;It is possible to execute JS through attributes like `onload` or `onmouseenter`.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Create a page with the following contents:
```html
&amp;lt;div class=&amp;#34;embedvideo-evl&amp;#34; data-iframeconfig=&amp;#39;{&amp;#34;onload&amp;#34;: &amp;#34;alert(1)&amp;#34;}&amp;#39;&amp;gt;Click me!&amp;lt;/div&amp;gt;
&amp;lt;evlplayer&amp;gt;&amp;lt;/evlplayer&amp;gt;
```
2. Click on the &amp;#34;Click me!&amp;#34; text
3. Click on the &amp;#34;Load video&amp;#34; button below
&amp;lt;img width=&amp;#34;855&amp;#34; height=&amp;#34;404&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/afb3839a-012c-4e90-a208-a6137b704ccd&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### Impact
Arbitrary HTML can be inserted into the DOM by any user, allowing for JavaScript to be executed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: starcitizenwiki/embedvideo&lt;/p&gt;
&lt;p&gt;### Summary
The EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The attributes of an iframe are populated with the value of an unreserved data attribute (`data-iframeconfig`) that can be set via wikitext:
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/blob/440fb331a84b2050f4cc084c1d31d58a1d1c202d/resources/ext.embedVideo.videolink.js#L5-L20
Similar code is also present here:
https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/blob/440fb331a84b2050f4cc084c1d31d58a1d1c202d/resources/modules/iframe.js#L139-L155&lt;/p&gt;
&lt;p&gt;It is possible to execute JS through attributes like `onload` or `onmouseenter`.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Create a page with the following contents:
```html
&amp;lt;div class=&amp;#34;embedvideo-evl&amp;#34; data-iframeconfig=&amp;#39;{&amp;#34;onload&amp;#34;: &amp;#34;alert(1)&amp;#34;}&amp;#39;&amp;gt;Click me!&amp;lt;/div&amp;gt;
&amp;lt;evlplayer&amp;gt;&amp;lt;/evlplayer&amp;gt;
```
2. Click on the &amp;#34;Click me!&amp;#34; text
3. Click on the &amp;#34;Load video&amp;#34; button below
&amp;lt;img width=&amp;#34;855&amp;#34; height=&amp;#34;404&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/afb3839a-012c-4e90-a208-a6137b704ccd&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### Impact
Arbitrary HTML can be inserted into the DOM by any user, allowing for JavaScript to be executed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4j5h-mvj3-m48v</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2341 — MediaWiki Extensions: Mehrere Schwachstellen ermöglichen Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2341</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um beliebigen Code oder SQL-Befehle auszuführen, Cross-Site-Scripting-Angriffe durchzuführen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in MediaWiki ausnutzen, um beliebigen Code oder SQL-Befehle auszuführen, Cross-Site-Scripting-Angriffe durchzuführen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2341</guid>
    </item>
  </channel>
</rss>
