<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:10:36 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-325667</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-325667</link>
      <description>EUVD-2026-325667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-325667</guid>
    </item>
    <item>
      <title>fkie_cve-2026-47344</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47344</link>
      <description>&lt;p&gt;When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., &amp;lt;/style\t&amp;gt;) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., &amp;lt;/style\t&amp;gt;) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-47344</guid>
    </item>
    <item>
      <title>GHSA-jvf5-rxvv-3mcg — TYPO3 HTML Sanitizer allows Cross-site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jvf5-rxvv-3mcg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: typo3/html-sanitizer&lt;/p&gt;
&lt;p&gt;When `ALLOW_INSECURE_RAW_TEXT` is enabled, whitespace-variant closing tags (e.g., `&amp;lt;/style\\t&amp;gt;`) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of `typo3/html-sanitizer` before version 2.3.2.&lt;/p&gt;
&lt;p&gt;Credits to IPC Labs for reporting this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: typo3/html-sanitizer&lt;/p&gt;
&lt;p&gt;When `ALLOW_INSECURE_RAW_TEXT` is enabled, whitespace-variant closing tags (e.g., `&amp;lt;/style\\t&amp;gt;`) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of `typo3/html-sanitizer` before version 2.3.2.&lt;/p&gt;
&lt;p&gt;Credits to IPC Labs for reporting this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jvf5-rxvv-3mcg</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1835 — TYPO3 Core: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1835</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in TYPO3 Core ausnutzen, um Sicherheitsbeschränkungen zu umgehen, Benutzer auf schädliche Websites umzuleiten, beliebigen Code auszuführen, Berechtigungen zu eskalieren oder andere Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in TYPO3 Core ausnutzen, um Sicherheitsbeschränkungen zu umgehen, Benutzer auf schädliche Websites umzuleiten, beliebigen Code auszuführen, Berechtigungen zu eskalieren oder andere Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1835</guid>
    </item>
  </channel>
</rss>
