<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 14:34:31 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-274052</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274052</link>
      <description>EUVD-2026-274052</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274052</guid>
    </item>
    <item>
      <title>fkie_cve-2026-3455</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-3455</link>
      <description>&lt;p&gt;Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker can execute arbitrary scripts in victim browsers by adding extra quote  &amp;#34; to the URL with embedded malicious JavaScript code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker can execute arbitrary scripts in victim browsers by adding extra quote  &amp;#34; to the URL with embedded malicious JavaScript code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-3455</guid>
    </item>
    <item>
      <title>GHSA-7gmj-h9xc-mcxc — mailparser vulnerable to Cross-site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7gmj-h9xc-mcxc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mailparser&lt;/p&gt;
&lt;p&gt;Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker can execute arbitrary scripts in victim browsers by adding extra quote  &amp;#34; to the URL with embedded malicious JavaScript code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mailparser&lt;/p&gt;
&lt;p&gt;Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker can execute arbitrary scripts in victim browsers by adding extra quote  &amp;#34; to the URL with embedded malicious JavaScript code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7gmj-h9xc-mcxc</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0710 — IBM App Connect Enterprise: Schwachstelle ermöglicht Cross-Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0710</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0710</guid>
    </item>
  </channel>
</rss>
