<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:43:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-291671</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291671</link>
      <description>EUVD-2026-291671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291671</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40104</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40104</link>
      <description>&lt;p&gt;XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc-1, 17.0.0-rc-1 and 17.5.0-rc-1 and prior include a resource exhaustion vulnerability in REST API endpoints such as /xwiki/rest/wikis/xwiki/spaces/AnnotationCode/pages/AnnotationConfig/objects/AnnotationCode.AnnotationConfig/0/properties, which list all available pages as part of the metadata for database list properties without applying query limits. On large wikis, this can exhaust available server resources. This issue has been patched in versions 16.10.16, 17.4.8 and 17.10.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc-1, 17.0.0-rc-1 and 17.5.0-rc-1 and prior include a resource exhaustion vulnerability in REST API endpoints such as /xwiki/rest/wikis/xwiki/spaces/AnnotationCode/pages/AnnotationConfig/objects/AnnotationCode.AnnotationConfig/0/properties, which list all available pages as part of the metadata for database list properties without applying query limits. On large wikis, this can exhaust available server resources. This issue has been patched in versions 16.10.16, 17.4.8 and 17.10.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40104</guid>
    </item>
    <item>
      <title>GHSA-mrqg-xmgm-rc5g — XWiki's REST APIs can list all pages/spaces, leading to unavailability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mrqg-xmgm-rc5g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xwiki.platform:xwiki-platform-oldcore, Maven: org.xwiki.platform:xwiki-platform-legacy-oldcore&lt;/p&gt;
&lt;p&gt;### Impact
REST API endpoints like `/xwiki/rest/wikis/xwiki/spaces/AnnotationCode/pages/AnnotationConfig/objects/AnnotationCode.AnnotationConfig/0/properties` list all available pages as part of the metadata for database list properties, which can exhaust available resources on large wikis.&lt;/p&gt;
&lt;p&gt;### Patches
This problem has been patched by applying the configured query limit also to the available values for database list properties in XWiki 16.10.16, 17.4.8 and 17.10.1.&lt;/p&gt;
&lt;p&gt;### Workarounds
We&amp;#39;re not aware of any workarounds apart from upgrading the affected modules.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xwiki.platform:xwiki-platform-oldcore, Maven: org.xwiki.platform:xwiki-platform-legacy-oldcore&lt;/p&gt;
&lt;p&gt;### Impact
REST API endpoints like `/xwiki/rest/wikis/xwiki/spaces/AnnotationCode/pages/AnnotationConfig/objects/AnnotationCode.AnnotationConfig/0/properties` list all available pages as part of the metadata for database list properties, which can exhaust available resources on large wikis.&lt;/p&gt;
&lt;p&gt;### Patches
This problem has been patched by applying the configured query limit also to the available values for database list properties in XWiki 16.10.16, 17.4.8 and 17.10.1.&lt;/p&gt;
&lt;p&gt;### Workarounds
We&amp;#39;re not aware of any workarounds apart from upgrading the affected modules.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mrqg-xmgm-rc5g</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1089 — xwiki: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1089</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in xwiki ausnutzen, um einen Denial of Service Angriff durchzuführen, und um einen Cross-Site Scripting Angriff durchzuühren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in xwiki ausnutzen, um einen Denial of Service Angriff durchzuführen, und um einen Cross-Site Scripting Angriff durchzuühren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1089</guid>
    </item>
  </channel>
</rss>
